Google: sys-kernel/cchost-kernel-6_12, sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_18: security update to 19907.0.0

medium Tenable Cloud Security Plugin ID 471444

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: fix stale stack
leak via the OIFNAME register For NFT_FIB_RESULT_OIFNAME the destination register is declared with len =
IFNAMSIZ (four 32-bit registers), but on the lookup-fail, RTN_LOCAL and oif-mismatch paths
nft_fib{4,6}_eval() only writes one register via "*dest = 0". The remaining three registers are left as
whatever was on the stack in nft_do_chain()'s struct nft_regs, and a downstream expression that loads the
register span can leak that uninitialised kernel stack to userspace. The NFTA_FIB_F_PRESENT existence
check has the same shape: it is only meaningful for NFT_FIB_RESULT_OIF, yet it was accepted for any result
type while the eval stores a single byte via nft_reg_store8(), leaving the rest of the declared span
stale. Fix both: - replace the bare "*dest = 0" in the eval with nft_fib_store_result(), which
strscpy_pad()s the whole IFNAMSIZ for OIFNAME (and is already used on the other early-return path), and -
restrict NFTA_FIB_F_PRESENT to NFT_FIB_RESULT_OIF and declare its destination as a single u8, so the
marked span matches the one byte the eval writes. (CVE-2026-53134)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19907.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 471444

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.63

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-53134

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/25/2026

Reference Information

CVE: CVE-2026-53134