Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 20085.0.0

high Tenable Cloud Security Plugin ID 472196

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xsk: clear metadata pointer when no
timestamp is requested User space can change metadata flags after request processing. Rereading them
during completion can therefore make the kernel write a timestamp that was not requested when the packet
was submitted. Clear the metadata pointer during request processing unless timestamp completion is
requested. Completion handling can then use the pointer itself instead of rereading the flags. On the mlx5
multi-packet WQE path metadata is evaluated per batch: xsk_tx_metadata_request() runs only for the
descriptor that starts a session, just like the checksum offload that is applied once through the shared
WQE. Only that descriptor's pointer is reset, so completion handling can record a timestamp for the other
descriptors of the session regardless of their own XDP_TXMD_FLAGS_TIMESTAMP bit. The write stays inside
the metadata area; the single-WQE, other zero-copy, and generic paths reset the pointer per descriptor and
are unaffected. (CVE-2026-74709)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 20085.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-138.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472196

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.44

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-74709

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/22/2026

Reference Information

CVE: CVE-2026-74709