Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 19999.44.28

medium Tenable Cloud Security Plugin ID 469751

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: futex: Fix race in
futex_pivot_pending() during private hash resize A task performing a custom private hash resize can remain
blocked in uninterruptible sleep indefinitely. The hung-task detector reports: INFO: task futex-
resizer:314 blocked for more than 10 seconds. task:futex-resizer state:D stack:14824 pid:314 tgid:312
ppid:311 Call Trace: __schedule+0x521/0xf30 schedule+0x22/0xa0 futex_hash_allocate+0x3db/0x490
__do_sys_prctl+0x6f5/0xbd0 do_syscall_64+0xf9/0x530 entry_SYSCALL_64_after_hwframe+0x77/0x7f Kernel panic
- not syncing: hung_task: blocked tasks futex_pivot_pending() allows the resize request to continue when
either no replacement hash is pending (hash_new == NULL) or the current hash reference count has reached
zero. After the final-reference wake, another futex task can complete the pivot between the two
observations: T1 T2 futex_hash_allocate() wait_var_event(mm, ...) futex_pivot_pending(mm) hash_new != NULL
futex_hash() futex_ref_get(old) -> false futex_pivot_hash(mm) hash_new = NULL __futex_pivot_hash(mm, new)
rcu_assign_pointer(hash, new) fph = rcu_dereference(hash) /* new */ futex_ref_is_dead(fph) -> false
schedule() The pivot changes the state from hash_new != NULL with a dead current hash to hash_new == NULL
with a live current hash. Because futex_pivot_pending() reads hash_new and hash without serialization, the
resize task can observe hash_new in the pre-pivot state and hash in the post-pivot state, causing
futex_pivot_pending() to return false even though the pivot has completed. The task then goes to sleep
after the wakeup has already been consumed. Serialize state reads in futex_pivot_pending() using
futex_mm_phash::lock. This guarantees that futex_pivot_pending() observes hash_new and hash atomically,
eliminating the race condition. (CVE-2026-80776)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 19999.44.28 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469751

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-80776

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/4/2026

Reference Information

CVE: CVE-2026-80776