Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19216.655.6

low Tenable Cloud Security Plugin ID 471901

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix matcher leak on
resize target setup failure hws_bwc_matcher_move() allocates a replacement matcher before setting it as
the resize target. If mlx5hws_matcher_resize_set_target() fails, the replacement matcher is not attached
anywhere and is leaked. Fix the leak by destroying the replacement matcher before returning from the
resize-target failure path. The bug was first flagged by an experimental analysis tool we are developing
for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is
not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1. An x86_64
allyesconfig build showed no new warnings. As we do not have a mlx5 HWS-capable device to test with, no
runtime testing was able to be performed. (CVE-2026-72032)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.655.6 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Low

ID: 471901

Version: Revision 1.2

Type: Local

Published: 10/3/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 1.4

Temporal Score: 1

Vector: CVSS2#AV:L/AC:L/Au:M/C:N/I:N/A:P

CVSS Score Source: CVE-2026-72032

CVSS v3

Risk Factor: Low

Base Score: 2.3

Temporal Score: 2

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-72032