Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.448.43

medium Tenable Self-Hosted Container Security Plugin ID 450938

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: tracing: Add
down_write(trace_event_sem) when adding trace event When a module is loaded, it adds trace events defined
by the module. It may also need to modify the modules trace printk formats to replace enum names with
their values. If two modules are loaded at the same time, the adding of the event to the ftrace_events
list can corrupt the walking of the list in the code that is modifying the printk format strings and crash
the kernel. The addition of the event should take the trace_event_sem for write while it adds the new
event. Also add a lockdep_assert_held() on that semaphore in __trace_add_event_dirs() as it iterates the
list. (CVE-2025-38539)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.448.43 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 450938

Version: Revision 1.3

Type: Local

Published: 10/1/2026

Updated: 10/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.34

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-38539

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2025-38539