Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 19999.44.21

high Tenable Cloud Security Plugin ID 469898

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: iomap: guard io_size EOF trim against
concurrent truncate underflow iomap: fix zero padding data issue in concurrent append writes changed ioend
accounting so that io_size tracks only valid data within EOF. This trims io_size when a writeback range
extends past end_pos: ioend->io_size += map_len; if (ioend->io_offset + ioend->io_size > end_pos)
ioend->io_size = end_pos - ioend->io_offset; However, if end_pos ends up below ioend->io_offset, the
subtraction becomes negative and is stored in size_t io_size, causing an unsigned wrap to a huge value.
This can happen when writeback continues past byte-level EOF up to a block-aligned range, or when a
concurrent truncate shrinks the file after end_pos was sampled in iomap_writeback_handle_eof(). A wrapped
io_size can mislead append detection and corrupt completion-time size handling, since filesystem end_io
paths consume io_size for decisions such as on-disk EOF updates and unwritten/COW completion ranges. Fix
this by clamping io_size to zero when EOF has moved to or before the ioend start offset. This preserves
the original intent of trimming io_size to valid in-EOF data while avoiding the underflow.
(CVE-2026-72367)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 19999.44.21 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469898

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.13

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-72367

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/15/2026

Reference Information

CVE: CVE-2026-72367