Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.164.4

medium Tenable Cloud Security Plugin ID 471716

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net/ipv6: release expired exception
dst cached in socket Dst objects get leaked in ip6_negative_advice() when this function is executed for an
expired IPv6 route located in the exception table. There are several conditions that must be fulfilled for
the leak to occur: * an ICMPv6 packet indicating a change of the MTU for the path is received, resulting
in an exception dst being created * a TCP connection that uses the exception dst for routing packets must
start timing out so that TCP begins retransmissions * after the exception dst expires, the FIB6 garbage
collector must not run before TCP executes ip6_negative_advice() for the expired exception dst When TCP
executes ip6_negative_advice() for an exception dst that has expired and if no other socket holds a
reference to the exception dst, the refcount of the exception dst is 2, which corresponds to the increment
made by dst_init() and the increment made by the TCP socket for which the connection is timing out. The
refcount made by the socket is never released. The refcount of the dst is decremented in sk_dst_reset()
but that decrement is counteracted by a dst_hold() intentionally placed just before the sk_dst_reset() in
ip6_negative_advice(). After ip6_negative_advice() has finished, there is no other object tied to the dst.
The socket lost its reference stored in sk_dst_cache and the dst is no longer in the exception table. The
exception dst becomes a leaked object. As a result of this dst leak, an unbalanced refcount is reported
for the loopback device of a net namespace being destroyed under kernels that do not contain e5f80fcf869a
("ipv6: give an IPv6 dev to blackhole_netdev"): unregister_netdevice: waiting for lo to become free. Usage
count = 2 Fix the dst leak by removing the dst_hold() in ip6_negative_advice(). The patch that introduced
the dst_hold() in ip6_negative_advice() was 92f1655aa2b22 ("net: fix __dst_negative_advice() race"). But
92f1655aa2b22 merely refactored the code with regards to the dst refcount so the issue was present even
before 92f1655aa2b22. The bug was introduced in 54c1a859efd9f ("ipv6: Don't drop cache route entry unless
timer actually expired.") where the expired cached route is deleted and the sk_dst_cache member of the
socket is set to NULL by calling dst_negative_advice() but the refcount belonging to the socket is left
unbalanced. The IPv4 version - ipv4_negative_advice() - is not affected by this bug. When the TCP
connection times out ipv4_negative_advice() merely resets the sk_dst_cache of the socket while
decrementing the refcount of the exception dst. (CVE-2024-56644)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.164.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 471716

Version: Revision 1.3

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-56644

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/12/2023

Reference Information

CVE: CVE-2024-56644