Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12: security update to 19216.220.24

medium Tenable Cloud Security Plugin ID 472063

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm, shmem: prevent infinite loop on
truncate race When truncating a large swap entry, shmem_free_swap() returns 0 when the entry's index
doesn't match the given index due to lookup alignment. The failure fallback path checks if the entry
crosses the end border and aborts when it happens, so truncate won't erase an unexpected entry or range.
But one scenario was ignored. When `index` points to the middle of a large swap entry, and the large swap
entry doesn't go across the end border, find_get_entries() will return that large swap entry as the first
item in the batch with `indices[0]` equal to `index`. The entry's base index will be smaller than
`indices[0]`, so shmem_free_swap() will fail and return 0 due to the "base < index" check. The code will
then call shmem_confirm_swap(), get the order, check if it crosses the END boundary (which it doesn't),
and retry with the same index. The next iteration will find the same entry again at the same index with
same indices, leading to an infinite loop. Fix this by retrying with a round-down index, and abort if the
index is smaller than the truncate range. (CVE-2026-23177)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.220.24 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472063

Version: Revision 1.2

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.87

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-23177

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2/14/2026

Reference Information

CVE: CVE-2026-23177