Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19216.700.7

high Tenable Cloud Security Plugin ID 471833

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: md: recheck spare changes before
starting sync remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These
operations are only safe after the array has been suspended. md_start_sync() checks whether spare
configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before
the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may
remove or replace rdevs while normal I/O is still accessing them. The race can occur as follows: raid10d
Worker Normal IO ____________ _______________________ ______________________ raid10_write_request()
wait_blocked_dev() set Blocked set Faulty Skip Faulty rdev rrdev->nr_pending++ .repl_bio = bio
removeable_rdev = false . array not suspended . lock mddev goto err_handle lock mddev (wait) . update sb .
clear Blocked . . unlock mddev . lock mddev (acquires) remove_spares() removeable_rdev = true
raid10_remove_disk() rdev = replacement replacement = NULL rdev_dec_pending(NULL) unlock mddev
(NULL)->nr_pending-- In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL
pointer dereference when attempting to decrement nr_pending. Fix this by suspending the array when spare
configuration changes are needed, including for non-read-write arrays, and checking again after taking
reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex,
suspend the array, and reacquire the mutex before continuing. (CVE-2026-90400)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.700.7 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 471833

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.41

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2026-90400

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/17/2026

Reference Information

CVE: CVE-2026-90400