Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.448.8

critical Tenable Cloud Security Plugin ID 469934

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before
tearing down scalable-mode context entry device_pasid_table_teardown() zeroes the 128-bit scalable-mode
context entry with context_clear_entry() while the Present bit is still set. This creates a window where
the hardware can fetch a torn entry, with some fields already zeroed while Present is still set, leading
to unpredictable behavior or spurious faults. The context-cache invalidation is issued only after the
entry has been zeroed, and intel_pasid_free_table() then frees the PASID directory pages, so the IOMMU can
keep walking a stale Present=1 entry that points at freed memory. While x86 provides strong write
ordering, the compiler may reorder the two 64-bit writes to the entry, and the hardware fetch is not
guaranteed to be atomic with respect to multiple CPU writes. Commit c1e4f1dccbe9d ("iommu/vt-d: Clear
Present bit before tearing down context entry") fixed this exact pattern in domain_context_clear_one() and
the copied-context path, but device_pasid_table_teardown() was not converted. Align it with the "Guidance
to Software for Invalidations" in the VT-d spec, Section 6.5.3.3, using the same ownership handshake as
the sibling fix: clear only the Present bit, flush it to the IOMMU, perform the context-cache
invalidation, and only then zero the rest of the entry. (CVE-2026-74439)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.448.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 469934

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.75

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74439

CVSS v3

Risk Factor: Critical

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-74439