Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 20085.0.0

high Tenable Cloud Security Plugin ID 472268

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handled
unaligned addresses huge_ptep_get() can be handed a virtual address pointing to the middle of a
contpmd/contpte mapped hugetlb folio (examples of callers are pagemap_hugetlb_range, page_mapped_in_vma).
The arm64 helper rewalks the pgtables in find_num_contig to answer whether the huge pte we have maps a
contpmd or a contpte hugetlb folio, and returns CONT_PMDS or CONT_PTES, so that it can collect a/d bits
over the contiguous ptes. We can falsely return CONT_PTES instead of CONT_PMDS if the addr is not aligned.
On systems where CONT_PTES != CONT_PMDS (meaning page size is 16K), we could collect excess A/D bit state,
meaning extra work for the kernel. Even worse, we may iterate beyond the PTE table and dereference a
garbage ptep pointer to access physical memory we don't own. Since the ptep pointer is a linear map
address, we may run off the end of the linear map or into a hole, dereference a VA not mapped into the
kernel pgtables and cause kernel panic. Fix this by aligning the pmdp pointer down to a contpmd base
before checking equality with the passed huge pte pointer, to correctly answer whether the huge pte is the
base of a contpmd block. (CVE-2026-68172)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 20085.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-138.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472268

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.58

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2026-68172

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/10/2026

Reference Information

CVE: CVE-2026-68172