Google: sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6: security update to 18613.0.99

medium Tenable Cloud Security Plugin ID 472347

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings
around in error case As Jann points out, PFN mappings are special, because unlike normal memory mappings,
there is no lifetime information associated with the mapping - it is just a raw mapping of PFNs with no
reference counting of a 'struct page'. That's all very much intentional, but it does mean that it's easy
to mess up the cleanup in case of errors. Yes, a failed mmap() will always eventually clean up any partial
mappings, but without any explicit lifetime in the page table mapping itself, it's very easy to do the
error handling in the wrong order. In particular, it's easy to mistakenly free the physical backing store
before the page tables are actually cleaned up and (temporarily) have stale dangling PTE entries. To make
this situation less error-prone, just make sure that any partial pfn mapping is torn down early, before
any other error handling. (CVE-2024-47674)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18613.0.99 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472347

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-47674

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 10/15/2024

Reference Information

CVE: CVE-2024-47674