Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.339.70

high Tenable Cloud Security Plugin ID 471379

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix stack memory use after
return in raid1_reshape In the raid1_reshape function, newpool is allocated on the stack and assigned to
conf->r1bio_pool. This results in conf->r1bio_pool.wait.head pointing to a stack address. Accessing this
address later can lead to a kernel panic. Example access path: raid1_reshape() { // newpool is on the
stack mempool_t newpool, oldpool; // initialize newpool.wait.head to stack address mempool_init(&newpool,
...); conf->r1bio_pool = newpool; } raid1_read_request() or raid1_write_request() { alloc_r1bio() {
mempool_alloc() { // if pool->alloc fails remove_element() { --pool->curr_nr; } } } } mempool_free() { if
(pool->curr_nr < pool->min_nr) { // pool->wait.head is a stack address // wake_up() will try to access
this invalid address // which leads to a kernel panic return; wake_up(&pool->wait); } } Fix: reinit
conf->r1bio_pool.wait after assigning newpool. (CVE-2025-38445)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.339.70 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 471379

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/7/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.35

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2025-38445

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2025-38445