Google: sys-kernel/cchost-kernel-6_12, sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_18: security update to 19999.44.21

medium Tenable Cloud Security Plugin ID 471318

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NMI/tracepoint re-entry
deadlock on lru locks NMI and tracepoint BPF programs can re-enter the per-CPU or global LRU lock that
bpf_lru_pop_free()/push_free() already hold on the same CPU, AA-deadlocking. Lockdep reports "inconsistent
{INITIAL USE} -> {IN-NMI}" on &l->lock (syzbot c69a0a2c816716f1e0d5) and "possible recursive locking
detected" on &loc_l->lock (syzbot 18b26edb69b2e19f3b33). Prior trylock and rqspinlock based fixes (see
links) were nacked because compromised on reliability. This patch converts every LRU lock site to
rqspinlock_t and adds a recovery path for some failure windows to avoid node leaks. Failure recovery: -
*_pop_free top-level: return NULL; prealloc_lru_pop() already treats that as no-free-element (-ENOMEM). -
Cross-CPU steal: skip the victim's locked loc_l, try next CPU. - Post-steal local lock fail: publish
stolen node to lockless per-CPU free_llist; next pop on this CPU picks it up. - push_free fail: mark node
pending_free=1. __local_list_flush(), __local_list_pop_pending() reclaim the node from pending_list.
__bpf_lru_list_shrink_inactive() reclaims the node from inactive list. Nodes from active list are
reclaimed by __bpf_lru_list_shrink() or after __bpf_lru_list_rotate_active() demotes it to the inactive.
(CVE-2026-74337)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19999.44.21 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 471318

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.36

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-74337

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/15/2026

Reference Information

CVE: CVE-2026-74337