Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.448.36

critical Tenable Self-Hosted Container Security Plugin ID 450986

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length
records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number
of them) - one non-DATA record If the next record has different type than what has already been processed
we break out of the main processing loop. If the record has already been decrypted (which may be the case
for TLS 1.3 where we don't know type until decryption) we queue the pending record to the rx_list. Next
recvmsg() will pick it up from there. Queuing the skb to rx_list after zero-copy decrypt is not possible,
since in that case we decrypted directly to the user space buffer, and we don't have an skb to queue
(darg.skb points to the ciphertext skb for access to metadata like length). Only data records are allowed
zero-copy, and we break the processing loop after each non-data record. So we should never zero-copy and
then find out that the record type has changed. The corner case we missed is when the initial record comes
from rx_list, and it's zero length. (CVE-2025-39682)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.448.36 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 450986

Version: Revision 1.3

Type: Local

Published: 10/1/2026

Updated: 10/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Critical

Score: 9.2

Percentile: 99.77

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-39682

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 9/5/2025

CISA Known Exploited Vulnerability Due Dates: 9/21/2026

Reference Information

CVE: CVE-2025-39682