Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12: security update to 19506.120.52

high Tenable Cloud Security Plugin ID 472200

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: Input: uinput - fix circular locking
dependency with ff-core A lockdep circular locking dependency warning can be triggered reproducibly when
using a force-feedback gamepad with uinput (for example, playing ELDEN RING under Wine with a Flydigi
Vader 5 controller): ff->mutex -> udev->mutex -> input_mutex -> dev->mutex -> ff->mutex The cycle is
caused by four lock acquisition paths: 1. ff upload: input_ff_upload() holds ff->mutex and calls
uinput_dev_upload_effect() -> uinput_request_submit() -> uinput_request_send(), which acquires
udev->mutex. 2. device create: uinput_ioctl_handler() holds udev->mutex and calls uinput_create_device()
-> input_register_device(), which acquires input_mutex. 3. device register: input_register_device() holds
input_mutex and calls kbd_connect() -> input_register_handle(), which acquires dev->mutex. 4. evdev
release: evdev_release() calls input_flush_device() under dev->mutex, which calls input_ff_flush()
acquiring ff->mutex. Fix this by introducing a new state_lock spinlock to protect udev->state and
udev->dev access in uinput_request_send() instead of acquiring udev->mutex. The function only needs to
atomically check device state and queue an input event into the ring buffer via uinput_dev_event() -- both
operations are safe under a spinlock (ktime_get_ts64() and wake_up_interruptible() do not sleep). This
breaks the ff->mutex -> udev->mutex link since a spinlock is a leaf in the lock ordering and cannot form
cycles with mutexes. To keep state transitions visible to uinput_request_send(), protect writes to
udev->state in uinput_create_device() and uinput_destroy_device() with the same state_lock spinlock.
Additionally, move init_completion(&request->done) from uinput_request_send() to uinput_request_submit()
before uinput_request_reserve_slot(). Once the slot is allocated, uinput_flush_requests() may call
complete() on it at any time from the destroy path, so the completion must be initialised before the
request becomes visible. Lock ordering after the fix: ff->mutex -> state_lock (spinlock, leaf) udev->mutex
-> state_lock (spinlock, leaf) udev->mutex -> input_mutex -> dev->mutex -> ff->mutex (no back-edge)
(CVE-2026-31667)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.120.52 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472200

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.92

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31667

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/23/2026

Reference Information

CVE: CVE-2026-31667