Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.299.20

high Tenable Cloud Security Plugin ID 472152

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fhandle: fix UAF due to unlocked
->mnt_ns read in may_decode_fh() may_decode_fh() accesses mount::mnt_ns without holding any locks; that
means the mount can concurrently be unmounted, and the mnt_namespace can concurrently be freed after an
RCU grace period. This race can happens as follows, assuming that the mount point was created by
open_tree(..., OPEN_TREE_CLONE): thread 1 thread 2 RCU __do_sys_open_by_handle_at do_handle_open
handle_to_path may_decode_fh is_mounted [mount::mnt_ns access] [mount::mnt_ns access] __do_sys_close
fput_close_sync __fput dissolve_on_fput umount_tree class_namespace_excl_destructor namespace_unlock
free_mnt_ns mnt_ns_tree_remove call_rcu(mnt_ns_release_rcu) mnt_ns_release_rcu mnt_ns_release kfree
[mnt_namespace::user_ns access] **UAF** Fix it by taking rcu_read_lock() around the mount::mnt_ns access,
like in __prepend_path(). Additionally, document the semantics of mount::mnt_ns, and use WRITE_ONCE() for
writers that can race with lockless readers. This bug is unreachable unless one of the following is set: -
CONFIG_PREEMPTION - CONFIG_RCU_STRICT_GRACE_PERIOD because it requires an RCU grace period to happen
during a syscall without an explicit preemption. This doesn't seem to have interesting security impact;
worst-case, it could leak the result of an integer comparison to userspace (from the level check in
cap_capable()), cause an endless loop, or crash the kernel by dereferencing an invalid address.
(CVE-2026-53341)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.299.20 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472152

Version: Revision 1.2

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.14

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53341

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/1/2026

Reference Information

CVE: CVE-2026-53341