Google: sys-kernel/lakitu-kernel-6_1: security update to 17935.0.0

high Tenable Self-Hosted Container Security Plugin ID 450532

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: drivers: base: Free devm resources
when unregistering a device In the current code, devres_release_all() only gets called if the device has a
bus and has been probed. This leads to issues when using bus-less or driver-less devices where the device
might never get freed if a managed resource holds a reference to the device. This is happening in the DRM
framework for example. We should thus call devres_release_all() in the device_del() function to make sure
that the device-managed actions are properly executed when the device is unregistered, even if it has
neither a bus nor a driver. This is effectively the same change than commit 2f8d16a996da ("devres: release
resources on device_del()") that got reverted by commit a525a3ddeaca ("driver core: free devres in
device_release") over memory leaks concerns. This patch effectively combines the two commits mentioned
above to release the resources both on device_del() and device_release() and get the best of both worlds.
(CVE-2023-53596)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 17935.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 450532

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.48

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-53596

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/3/2023

Reference Information

CVE: CVE-2023-53596