Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.505.8

high Tenable Cloud Security Plugin ID 470013

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in
read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off =
lsn_to_page_off(log, lsn) + log->record_header_len; log->record_header_len (and log->data_off, used for
the following pages) comes verbatim from the on-disk restart area and is only checked for 8-byte alignment
in is_rst_area_valid(), so off can exceed log->page_size. "tail = log->page_size - off" then underflows
and memcpy() reads past the page_size-sized buffer returned by read_log_page(), spilling adjacent slab
memory into the replay buffer. This is reachable by mounting a crafted NTFS image: BUG: KASAN: slab-out-
of-bounds in read_log_rec_buf+0x216/0x580 Read of size 64 at addr ffff88800a877ff8 by task exploit/127
read_log_rec_buf fs/ntfs3/fslog.c:2299 log_replay fs/ntfs3/fslog.c:4216 ntfs_loadlog_and_replay
fs/ntfs3/fsntfs.c:324 ntfs_fill_super fs/ntfs3/super.c:1392 get_tree_bdev_flags fs/super.c:1694
__x64_sys_mount fs/namespace.c:4360 The buggy address is located 4088 bytes to the right of the 4096-byte
region [ffff88800a876000, ffff88800a877000) Reject an in-page offset outside the current page before the
copy. [[email protected]: replaced the >= sign with >] (CVE-2026-89781)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.505.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 470013

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.25

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-89781

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-89781