Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12: security update to 19506.0.98

medium Tenable Cloud Security Plugin ID 469836

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in
attr_load_runs_range on inconsistent metadata We found an infinite loop bug in the ntfs3 file system that
can lead to a Denial-of-Service (DoS) condition. A malformed NTFS image can cause an infinite loop when an
attribute header indicates an empty run list, while directory entries reference it as containing actual
data. In NTFS, setting evcn=-1 with svcn=0 is a valid way to represent an empty run list, and run_unpack()
correctly handles this by checking if evcn + 1 equals svcn and returning early without parsing any run
data. However, this creates a problem when there is metadata inconsistency, where the attribute header
claims to be empty (evcn=-1) but the caller expects to read actual data. When run_unpack() immediately
returns success upon seeing this condition, it leaves the runs_tree uninitialized with run->runs as a
NULL. The calling function attr_load_runs_range() assumes that a successful return means that the runs
were loaded and sets clen to 0, expecting the next run_lookup_entry() call to succeed. Because runs_tree
remains uninitialized, run_lookup_entry() continues to fail, and the loop increments vcn by zero (vcn +=
0), leading to an infinite loop. This patch adds a retry counter to detect when run_lookup_entry() fails
consecutively after attr_load_runs_vcn(). If the run is still not found on the second attempt, it
indicates corrupted metadata and returns -EINVAL, preventing the Denial-of-Service (DoS) vulnerability.
(CVE-2025-71265)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.0.98 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469836

Version: Revision 1.2

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.76

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-71265

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 3/18/2026

Reference Information

CVE: CVE-2025-71265