Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.448.50

medium Tenable Self-Hosted Container Security Plugin ID 450959

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded
recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently,
ep_loop_check_proc() ensures that the graph is loop-free and does some recursion depth checks, but those
recursion depth checks don't limit the depth of the resulting tree for two reasons: - They don't look
upwards in the tree. - If there are multiple downwards paths of different lengths, only one of the paths
is actually considered for the depth check since commit 28d82dc1c4ed ("epoll: limit paths"). Essentially,
the current recursion depth check in ep_loop_check_proc() just serves to prevent it from recursing too
deeply while checking for loops. A more thorough check is done in reverse_path_check() after the new graph
edge has already been created; this checks, among other things, that no paths going upwards from any non-
epoll file with a length of more than 5 edges exist. However, this check does not apply to non-epoll
files. As a result, it is possible to recurse to a depth of at least roughly 500, tested on v6.15. (I am
unsure if deeper recursion is possible; and this may have changed with commit 8c44dac8add7 ("eventpoll:
Fix priority inversion problem").) To fix it: 1. In ep_loop_check_proc(), note the subtree depth of each
visited node, and use subtree depths for the total depth calculation even when a subtree has already been
visited. 2. Add ep_get_upwards_depth_proc() for similarly determining the maximum depth of an upwards
walk. 3. In ep_loop_check(), use these values to limit the total path length between epoll nodes to
EP_MAX_NESTS edges. (CVE-2025-38614)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.448.50 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 450959

Version: Revision 1.3

Type: Local

Published: 10/1/2026

Updated: 10/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.15

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-38614

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2025-38614