Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.85.5

high Tenable Self-Hosted Container Security Plugin ID 450615

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: wireguard: netlink: check for dangling
peer via is_dead instead of empty list If all peers are removed via wg_peer_remove_all(), rather than
setting peer_list to empty, the peer is added to a temporary list with a head on the stack of
wg_peer_remove_all(). If a netlink dump is resumed and the cursored peer is one that has been removed via
wg_peer_remove_all(), it will iterate from that peer and then attempt to dump freed peers. Fix this by
instead checking peer->is_dead, which was explictly created for this purpose. Also move up the
device_update_lock lockdep assertion, since reading is_dead relies on that. It can be reproduced by a
small script like: echo "Setting config..." ip link add dev wg0 type wireguard wg setconf wg0 /big-config
( while true; do echo "Showing config..." wg showconf wg0 > /dev/null done ) & sleep 4 wg setconf wg0
<(printf "[Peer]\nPublicKey=$(wg genkey)\n") Resulting in: BUG: KASAN: slab-use-after-free in
__lock_acquire+0x182a/0x1b20 Read of size 8 at addr ffff88811956ec70 by task wg/59 CPU: 2 PID: 59 Comm: wg
Not tainted 6.8.0-rc2-debug+ #5 Call Trace: <TASK> dump_stack_lvl+0x47/0x70
print_address_description.constprop.0+0x2c/0x380 print_report+0xab/0x250 kasan_report+0xba/0xf0
__lock_acquire+0x182a/0x1b20 lock_acquire+0x191/0x4b0 down_read+0x80/0x440 get_peer+0x140/0xcb0
wg_get_device_dump+0x471/0x1130 (CVE-2024-26951)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.85.5 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 450615

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.44

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-26951

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2024-26951