Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.299.137

medium Tenable Cloud Security Plugin ID 469502

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: exec: fix unsigned loop counter wrap
in transfer_args_to_stack() The stop value is derived from bprm->p >> PAGE_SHIFT. The index variable is an
unsigned long. If bprm->p drops below PAGE_SIZE and stop becomes zero the loop condition index >= stop is
always true. After the index == 0 iteration the decrement wraps to ULONG_MAX and bprm->page[ULONG_MAX]
reads sizeof(void *) bytes in front of the array. The pointer has wrapped to -1. That garbage pointer is
then passed to kmap_local_page() and PAGE_SIZE bytes are copied from wherever that lands into the stack of
the process being created. And the loop doesn't terminate either... Getting there only requires bprm->p <
PAGE_SIZE. On !MMU bprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only constraint on
how far bprm->p is pushed down is valid_arg_len(), i.e. that each individual string still fits in what is
left. bprm->p starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a single argument or environment
string of a little over 31 pages leaves it in the first page: Oops - load access fault [#1] CPU: 0 UID: 0
PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1 epc : __memcpy+0xd4/0xf8 ra :
transfer_args_to_stack+0xaa/0xae s4 : ffffffffffffffff s2 : 0000000000000000 a1 : ffffffdc98000000 a2 :
0000000000001000 status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005 [<801a5324>]
__memcpy+0xd4/0xf8 [<800d5f6a>] load_flat_binary+0x43a/0x65e [<800a2de4>] bprm_execve+0x1d4/0x316
[<800a351a>] do_execveat_common+0x12e/0x138 [<800a3d44>] __riscv_sys_execve+0x38/0x4e Kernel panic - not
syncing: Fatal exception in interrupt This is an arcane bug but we should still fix it. Count down from
MAX_ARG_PAGES so the loop ends when index reaches stop, stop == 0 included. The iterations performed are
unchanged for every other value of stop. Only CONFIG_MMU=n builds are affected, transfer_args_to_stack()
is used by binfmt_flat and binfmt_elf_fdpic on nommu only. The loop predates git history. commit
7e7ec6a93434 ("elf_fdpic_transfer_args_to_stack(): make it generic") only moved it from binfmt_elf_fdpic.c
into fs/exec.c and narrowed the copy to the used part of the first page. The condition and the decrement
are unchanged from 2.6.12-rc2. (CVE-2026-68187)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.299.137 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469502

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.82

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:N/A:C

CVSS Score Source: CVE-2026-68187

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/10/2026

Reference Information

CVE: CVE-2026-68187