Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 20098.0.0

high Tenable Cloud Security Plugin ID 471416

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: futex: Fix race on the initial
mm->futex.phash.ref allocation futex_hash_allocate() allocates mm->futex.phash.ref without any locking.
Commit d9b05321e21e ("futex: Move futex_hash_free() back to __mmput()") moved the allocation here and
assumed that the process has just a single thread at this point. Commit ee9dce44362b ("futex: Drop
CLONE_THREAD requirement for private default hash alloc") widened need_futex_hash_allocate_default() to
cover any CLONE_VM clone, but left out vfork because the parent is suspended and cannot race. That no
longer holds once vfork is nested. If a vfork child calls vfork again and is then killed with SIGKILL, the
parent is released from its vfork wait and runs concurrently with the grandchild in the same mm. Neither
of them went through futex_hash_allocate_default(). When both call prctl(PR_FUTEX_HASH,
PR_FUTEX_HASH_SET_SLOTS) at the same time, each one sees mm->futex.phash.ref as NULL and stores its own
percpu counter. Only the last store survives. The counter stored first is no longer reachable from the mm,
so the references on it are not seen by __futex_ref_atomic_end(). A private hash that still has references
is then considered dead and freed, and a task that still holds one of its buckets writes into freed memory
in futex_q_lock(). Store the counter once with cmpxchg() and let the loser free_percpu() its own. The
initial reference has to be taken before the store, otherwise another task can install a private hash
while the counter is still 0. (CVE-2026-80775)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 20098.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-138.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 471416

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.39

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.4

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-80775

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/4/2026

Reference Information

CVE: CVE-2026-80775