Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.85.5

medium Tenable Self-Hosted Container Security Plugin ID 450628

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: rtnetlink: fix error logic of
IFLA_BRIDGE_FLAGS writing back In the commit d73ef2d69c0d ("rtnetlink: let rtnl_bridge_setlink checks
IFLA_BRIDGE_MODE length"), an adjustment was made to the old loop logic in the function
`rtnl_bridge_setlink` to enable the loop to also check the length of the IFLA_BRIDGE_MODE attribute.
However, this adjustment removed the `break` statement and led to an error logic of the flags writing back
at the end of this function. if (have_flags) memcpy(nla_data(attr), &flags, sizeof(flags)); // attr should
point to IFLA_BRIDGE_FLAGS NLA !!! Before the mentioned commit, the `attr` is granted to be
IFLA_BRIDGE_FLAGS. However, this is not necessarily true fow now as the updated loop will let the attr
point to the last NLA, even an invalid NLA which could cause overflow writes. This patch introduces a new
variable `br_flag` to save the NLA pointer that points to IFLA_BRIDGE_FLAGS and uses it to resolve the
mentioned error logic. (CVE-2024-27414)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.85.5 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 450628

Version: Revision 1.2

Type: Local

Published: 10/1/2026

Updated: 10/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-27414

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2024-27414