Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 19862.0.0

medium Tenable Cloud Security Plugin ID 470221

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: md: fix array_state=clear sysfs
deadlock When "clear" is written to array_state, md_attr_store() breaks sysfs active protection so the
array can delete itself from its own sysfs store method. However, md_attr_store() currently drops the
mddev reference before calling sysfs_unbreak_active_protection(). Once do_md_stop(..., 0) has made the
mddev eligible for delayed deletion, the temporary kobject reference taken by
sysfs_break_active_protection() can become the last kobject reference protecting the md kobject. That
allows sysfs_unbreak_active_protection() to drop the last kobject reference from the current sysfs writer
context. kobject teardown then recurses into kernfs removal while the current sysfs node is still being
unwound, and lockdep reports recursive locking on kn->active with kernfs_drain() in the call chain.
Reproducer on an existing level: 1. Create an md0 linear array and activate it: mknod /dev/md0 b 9 0 echo
none > /sys/block/md0/md/metadata_version echo linear > /sys/block/md0/md/level echo 1 >
/sys/block/md0/md/raid_disks echo "$(cat /sys/class/block/sdb/dev)" > /sys/block/md0/md/new_dev echo
"$(($(cat /sys/class/block/sdb/size) / 2))" > \ /sys/block/md0/md/dev-sdb/size echo 0 >
/sys/block/md0/md/dev-sdb/slot echo active > /sys/block/md0/md/array_state 2. Wait briefly for the array
to settle, then clear it: sleep 2 echo clear > /sys/block/md0/md/array_state The warning looks like:
WARNING: possible recursive locking detected bash/588 is trying to acquire lock: (kn->active#65) at
__kernfs_remove+0x157/0x1d0 but task is already holding lock: (kn->active#65) at
sysfs_unbreak_active_protection+0x1f/0x40 ... Call Trace: kernfs_drain __kernfs_remove
kernfs_remove_by_name_ns sysfs_remove_group sysfs_remove_groups __kobject_del kobject_put md_attr_store
kernfs_fop_write_iter vfs_write ksys_write Restore active protection before mddev_put() so the extra sysfs
kobject reference is dropped while the mddev is still held alive. The actual md kobject deletion is then
deferred until after the sysfs write path has fully returned. (CVE-2026-53125)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 19862.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 470221

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.96

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-53125

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/22/2026

Reference Information

CVE: CVE-2026-53125