Google: sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.0.87

medium Tenable Cloud Security Plugin ID 472493

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: cgroup: split cgroup_destroy_wq into 3
workqueues A hung task can occur during [1] LTP cgroup testing when repeatedly mounting/unmounting
perf_event and net_prio controllers with systemd.unified_cgroup_hierarchy=1. The hang manifests in
cgroup_lock_and_drain_offline() during root destruction. Related case: cgroup_fj_function_perf_event
cgroup_fj_function.sh perf_event cgroup_fj_function_net_prio cgroup_fj_function.sh net_prio Call Trace:
cgroup_lock_and_drain_offline+0x14c/0x1e8 cgroup_destroy_root+0x3c/0x2c0 css_free_rwork_fn+0x248/0x338
process_one_work+0x16c/0x3b8 worker_thread+0x22c/0x3b0 kthread+0xec/0x100 ret_from_fork+0x10/0x20 Root
Cause: CPU0 CPU1 mount perf_event umount net_prio cgroup1_get_tree cgroup_kill_sb rebind_subsystems //
root destruction enqueues // cgroup_destroy_wq // kill all perf_event css // one perf_event css A is dying
// css A offline enqueues cgroup_destroy_wq // root destruction will be executed first css_free_rwork_fn
cgroup_destroy_root cgroup_lock_and_drain_offline // some perf descendants are dying // cgroup_destroy_wq
max_active = 1 // waiting for css A to die Problem scenario: 1. CPU0 mounts perf_event (rebind_subsystems)
2. CPU1 unmounts net_prio (cgroup_kill_sb), queuing root destruction work 3. A dying perf_event CSS gets
queued for offline after root destruction 4. Root destruction waits for offline completion, but offline
work is blocked behind root destruction in cgroup_destroy_wq (max_active=1) Solution: Split
cgroup_destroy_wq into three dedicated workqueues: cgroup_offline_wq – Handles CSS offline operations
cgroup_release_wq – Manages resource release cgroup_free_wq – Performs final memory deallocation This
separation eliminates blocking in the CSS free path while waiting for offline operations to complete. [1]
https://github.com/linux-test-project/ltp/blob/master/runtest/controllers (CVE-2025-39953)

Solution

Update the sys-kernel/csql-kernel-6_12 library and its related packages to version 19216.0.87 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472493

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.76

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-39953

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/4/2025

Reference Information

CVE: CVE-2025-39953