Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.299.3

medium Tenable Cloud Security Plugin ID 472240

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio->private handling in
netfs_perform_write() Under some circumstances, netfs_perform_write() doesn't correctly manipulate
folio->private between NULL, NETFS_FOLIO_COPY_TO_CACHE, pointing to a group and pointing to a netfs_folio
struct, leading to potential multiple attachments of private data with associated folio ref leaks and also
leaks of netfs_folio structs or netfs_group refs. Fix this by consolidating the place at which a folio is
marked uptodate in one place and having that look at what's attached to folio->private and decide how to
clean it up and then set the new group. Also, the content shouldn't be flushed if group is NULL, even if a
group is specified in the netfs_group parameter, as that would be the case for a new folio. A filesystem
should always specify netfs_group or never specify netfs_group. The Sashiko auto-review tool noted that it
was theoretically possible that the fpos >= ctx->zero_point section might leak if it modified a streaming
write folio. This is unlikely, but with a network filesystem, third party changes can happen. It also
pointed out that __netfs_set_group() would leak if called multiple times on the same folio from the "whole
folio modify section". (CVE-2026-64059)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.299.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472240

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.64

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-64059

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/4/2026

Reference Information

CVE: CVE-2026-64059