Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.448.8

critical Tenable Cloud Security Plugin ID 469993

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ntfs3: bound to_move in
indx_insert_into_root before hdr_insert_head indx_insert_into_root() promotes a full resident $INDEX_ROOT
into $INDEX_ALLOCATION and copies all non-last resident root entries into a newly allocated INDEX_BUFFER
via hdr_insert_head(). The source byte count 'to_move' is summed from the on-disk resident entry sizes and
is independent of the destination buffer size, which comes from root->index_block_size (via
indx->index_bits). A crafted NTFS image that keeps a valid, full resident root but shrinks
root->index_block_size down to 512 after the root has been populated makes hdr_insert_head() memcpy
attacker-controlled resident entry bytes past the end of the kmalloc(1u << indx->index_bits) allocation
returned by indx_new(). For a 512-byte destination and a resident root whose non-last entries total 560
bytes, the memcpy overruns by 120 bytes and a following memmove extends the highest written offset to 136
bytes past the allocation. The overflow bytes are a direct copy of on-disk entries (via kmemdup), so they
are fully attacker-controlled. The write is reachable from unprivileged open(O_CREAT) on a mounted crafted
NTFS image: a single sufficiently long create in a directory whose resident root is already full forces
root promotion and triggers the copy. This is a controlled out-of-bounds write of 120-136 bytes past a
kmalloc(index_block_size) allocation, with attacker-controlled content. It is a bounded adjacent-heap
corruption primitive; it is not an arbitrary-address write. Successful exploitation into a named victim
object depends on the surrounding slab layout. Reject the copy at the sink. The destination's INDEX_HDR
already reports hdr_total (the payload capacity of the new buffer) and hdr_used (the bytes already
consumed by the terminal END entry installed by indx_new()); require that to_move fits in the remaining
payload before calling hdr_insert_head(). On mismatch, fail with -EINVAL and mark the filesystem as having
a detected on-disk inconsistency, which is the same behaviour as the surrounding validation in this
function. (CVE-2026-72192)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.448.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 469993

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-72192

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-72192