Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12: security update to 19216.104.133

medium Tenable Cloud Security Plugin ID 472635

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: lib/buildid: use __kernel_read() for
sleepable context Prevent a "BUG: unable to handle kernel NULL pointer dereference in filemap_read_folio".
For the sleepable context, convert freader to use __kernel_read() instead of direct page cache access via
read_cache_folio(). This simplifies the faultable code path by using the standard kernel file reading
interface which handles all the complexity of reading file data. At the moment we are not changing the
code for non-sleepable context which uses filemap_get_folio() and only succeeds if the target folios are
already in memory and up-to-date. The reason is to keep the patch simple and easier to backport to stable
kernels. Syzbot repro does not crash the kernel anymore and the selftests run successfully. In the follow
up we will make __kernel_read() with IOCB_NOWAIT work for non-sleepable contexts. In addition, I would
like to replace the secretmem check with a more generic approach and will add fstest for the buildid code.
(CVE-2026-23002)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.104.133 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472635

Version: Revision 1.2

Type: Local

Published: 10/5/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.63

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-23002

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/25/2026

Reference Information

CVE: CVE-2026-23002