Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 20085.0.0

critical Tenable Cloud Security Plugin ID 470818

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned
file reference to accept_doit handshake_req_next() removes the request from the per-net pending list and
drops hn_lock before handshake_nl_accept_doit() reads req->hr_sk->sk_socket and dereferences sock->file
(once in FD_PREPARE() and again in get_file()). In that window a consumer running tls_handshake_cancel()
followed by sockfd_put() (svc_sock_free) or __fput_sync() (xs_reset_transport) releases sock->file.
sock_release() then runs sock_orphan(), zeroing sk_socket, and frees the struct socket. The accept-side
code either reads NULL through sk_socket or chases freed memory. The submit-side sock_hold() does not
prevent this. sk_refcnt protects struct sock, but struct socket and sock->file are independently
refcounted via the file descriptor the consumer owns. Pinning sk leaves sock and sock->file unprotected.
Retarget the accept-side dereferences at req->hr_file, which was pinned at submit time, instead of
req->hr_sk->sk_socket->file. Pinning on its own is not sufficient: a consumer that cancels between
handshake_req_next() returning and accept_doit reaching FD_PREPARE() takes the !remove_pending() branch in
handshake_req_cancel() and drops hr_file before the accept side takes its own reference. Hand off an
additional file reference inside handshake_req_next(), under hn_lock, so the accept side operates on a
reference that no concurrent handshake_req_cancel() can revoke. FD_PREPARE() consumes that handed-off
reference, either by transferring it to the new fd in fd_publish() or by dropping it in the cleanup
destructor on error; the explicit get_file() that previously balanced FD_PREPARE() is therefore redundant
and goes away. Update handshake_req_cancel_test2 and _test3 to simulate the FD_PREPARE() consumption with
an fput() so the kunit file-count assertions stay balanced. (CVE-2026-63979)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 20085.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-138.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 470818

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.86

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-63979

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/19/2026

Reference Information

CVE: CVE-2026-63979