Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.448.8

high Tenable Cloud Security Plugin ID 469616

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: blk-mq: pop cached request if it is
usable When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but
before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a
use-after-free bug. Fix this by popping the cached request before any possible blocking calls if it is
suitable for use. Popping this request first holds a queue reference, so avoid any serialization races
with queue freezes and can safely proceed with dispatching that request to the driver. This potentially
increases a timing window from when a driver wants to freeze its queue to when requests stop being
dispatched. That scenario is off the fast path though, and drivers need to appropriately handle requests
during a freeze request anyway. The downside is the popped element needs to be individually freed when we
performed a bio plug merge. The cached request would have had to be freed later anyway, but this patch
does it inline with building the plug list instead of after flushing it. (CVE-2026-64017)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.448.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469616

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.03

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64017

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/19/2026

Reference Information

CVE: CVE-2026-64017