Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 20098.0.0

medium Tenable Cloud Security Plugin ID 471549

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: io_uring/cmd: fix iovec leak when the
async cmd is not recycled An io_async_cmd carries an iovec array in ->vec.iovec, allocated when the vec
has to grow and kept across recycling through ctx->cmd_cache. On two paths nothing frees it and
io_clean_op()'s kfree(req->async_data) drops the io_async_cmd without it. io_req_uring_cleanup() clears
the async data flags only when io_alloc_cache_put() succeeds, and the cache holds IO_ALLOC_CACHE_MAX ==
128 entries, so once it is full the put fails and the vec is left behind. An NVMe passthrough workload
gets there without doing anything unusual: nvme_uring_cmd_io() returns -EIOCBQUEUED, so the io_async_cmd
stays attached for the lifetime of the command and the live object count tracks the queue depth. Above 128
the puts start failing. ->cleanup is the last chance to free an inherited vec, since
io_req_uring_cleanup() returns early for an io-wq issued command and is not called at all for one
completed without ever being issued. But io_clean_op() calls ->cleanup only if REQ_F_NEED_CLEANUP is set,
and for uring_cmd that happens only where the vec has to grow, so a command reusing a large enough cached
vec never sets it. io_rw_alloc_async() and io_msg_alloc_async() flag an inherited vec for exactly this
reason; io_uring_cmd_prep() does not. Flag an inherited vec in io_uring_cmd_prep(), and free the vec when
the cache put fails, as io_req_rw_cleanup() does. The leak is invisible under KASAN, where
io_alloc_cache_vec_kasan() frees the vec unconditionally. (CVE-2026-80811)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 20098.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-138.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 471549

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.44

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-80811

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/4/2026

Reference Information

CVE: CVE-2026-80811