Google: sys-kernel/lakitu-kernel-6_1: security update to 18244.236.64

medium Tenable Self-Hosted Container Security Plugin ID 450778

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ACPI: PRM: Find EFI_MEMORY_RUNTIME
block for PRM handler and context PRMT needs to find the correct type of block to translate the PA-VA
mapping for EFI runtime services. The issue arises because the PRMT is finding a block of type
EFI_CONVENTIONAL_MEMORY, which is not appropriate for runtime services as described in Section 2.2.2
(Runtime Services) of the UEFI Specification [1]. Since the PRM handler is a type of runtime service, this
causes an exception when the PRM handler is called. [Firmware Bug]: Unable to handle paging request in EFI
runtime service WARNING: CPU: 22 PID: 4330 at drivers/firmware/efi/runtime-wrappers.c:341
__efi_queue_work+0x11c/0x170 Call trace: Let PRMT find a block with EFI_MEMORY_RUNTIME for PRM handler and
PRM context. If no suitable block is found, a warning message will be printed, but the procedure continues
to manage the next PRM handler. However, if the PRM handler is actually called without proper allocation,
it would result in a failure during error handling. By using the correct memory types for runtime
services, ensure that the PRM handler and the context are properly mapped in the virtual address space
during runtime, preventing the paging request error. The issue is really that only memory that has been
remapped for runtime by the firmware can be used by the PRM handler, and so the region needs to have the
EFI_MEMORY_RUNTIME attribute. [ rjw: Subject and changelog edits ] (CVE-2024-50141)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18244.236.64 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 450778

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-50141

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 11/7/2024

Reference Information

CVE: CVE-2024-50141