Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 19999.44.21

high Tenable Cloud Security Plugin ID 472121

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: fix BPF_PROG_QUERY OOB write and
cgroup backward compat BPF_PROG_QUERY writes back the 'query.revision' field unconditionally to userspace.
If userspace passes a smaller 'bpf_attr' structure (e.g. 40 bytes, which was the layout before the
addition of 'query.revision'), the kernel performs an out-of-bounds write. Fix this by propagating the
user-provided attribute size 'uattr_size' down to the cgroup query handlers, and conditionally skipping
writing the revision field to userspace when the provided buffer size is insufficient. query.revision in
bpf_mprog_query is structurally identical to the cgroup case: a late tail field, written unconditionally.
But the backward-compat hazard is not the same. The min-historical-size test is per command, and
bpf_mprog_query only serves attach types that were born with revision in the struct: - tcx_prog_query ->
BPF_TCX_INGRESS/EGRESS - netkit_prog_query -> BPF_NETKIT_PRIMARY/PEER tcx, netkit, the revision field, and
bpf_mprog_query itself all landed in the same v6.6 merge window (053c8e1f235d added the mprog query API +
revision; tcx in e420bed02507, netkit in 35dfaad7188c). There has never been a tcx/netkit BPF_PROG_QUERY
userspace that doesn't know about revision. So for these commands the minimum legitimate struct already
covers offset 56-64 — no old binary can be broken here. Contrast with cgroup: BPF_PROG_QUERY on cgroup
attach types shipped in 2017; revision write-back was bolted on years later (120933984460). That path has
a real population of pre-revision callers. (CVE-2026-74371)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 19999.44.21 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472121

Version: Revision 1.2

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.37

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74371

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/15/2026

Reference Information

CVE: CVE-2026-74371