Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 19804.0.0

high Tenable Cloud Security Plugin ID 470466

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: writeback: Fix use after free in
inode_switch_wbs_work_fn() inode_switch_wbs_work_fn() has a loop like: wb_get(new_wb); while (1) { list =
llist_del_all(&new_wb->switch_wbs_ctxs); /* Nothing to do? */ if (!list) break; ... process the items ...
} Now adding of items to the list looks like: wb_queue_isw() if (llist_add(&isw->list,
&wb->switch_wbs_ctxs)) queue_work(isw_wq, &wb->switch_work); Because inode_switch_wbs_work_fn() loops when
processing isw items, it can happen that wb->switch_work is pending while wb->switch_wbs_ctxs is empty.
This is a problem because in that case wb can get freed (no isw items -> no wb reference) while the work
is still pending causing use-after-free issues. We cannot just fix this by cancelling work when freeing wb
because that could still trigger problematic 0 -> 1 transitions on wb refcount due to wb_get() in
inode_switch_wbs_work_fn(). It could be all handled with more careful code but that seems unnecessarily
complex so let's avoid that until it is proven that the looping actually brings practical benefit. Just
remove the loop from inode_switch_wbs_work_fn() instead. That way when wb_queue_isw() queues work, we are
guaranteed we have added the first item to wb->switch_wbs_ctxs and nobody is going to remove it (and drop
the wb reference it holds) until the queued work runs. (CVE-2026-31703)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 19804.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 470466

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31703

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/1/2026

Reference Information

CVE: CVE-2026-31703