Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 19999.44.21

critical Tenable Cloud Security Plugin ID 470322

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN
when mapping L1 VNCR KVM currently maps the L1 VNCR into the host stage-1 by relying entirely on the
permissions of the guest stage-1. At the same time, it is entirely possible that the backing PFN is read-
only (e.g. RO memslot), meaning that the L1 VNCR should use at most a read-only mapping. Cache the
writability of the PFN in the VNCR TLB and use it to constrain the resulting fixmap permissions. Promote
VNCR permission faults to an SEA in the case where the guest attempts to write to a read-only endpoint.
Conveniently, this also plugs a page leak found by Sashiko [*] resulting from the early return for a read-
only PFN. (CVE-2026-72279)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 19999.44.21 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 470322

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.82

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-72279

CVSS v3

Risk Factor: Critical

Base Score: 9

Temporal Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/15/2026

Reference Information

CVE: CVE-2026-72279