Google: sys-kernel/lakitu-kernel-6_1: security update to 18244.291.73

medium Tenable Self-Hosted Container Security Plugin ID 451002

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: tcp: drop secpath at the same time as
we currently drop dst Xiumei reported hitting the WARN in xfrm6_tunnel_net_exit while running tests that
boil down to: - create a pair of netns - run a basic TCP test over ipcomp6 - delete the pair of netns The
xfrm_state found on spi_byaddr was not deleted at the time we delete the netns, because we still have a
reference on it. This lingering reference comes from a secpath (which holds a ref on the xfrm_state),
which is still attached to an skb. This skb is not leaked, it ends up on sk_receive_queue and then gets
defer-free'd by skb_attempt_defer_free. The problem happens when we defer freeing an skb (push it on one
CPU's defer_list), and don't flush that list before the netns is deleted. In that case, we still have a
reference on the xfrm_state that we don't expect at this point. We already drop the skb's dst in the TCP
receive path when it's no longer needed, so let's also drop the secpath. At this point, tcp_filter has
already called into the LSM hooks that may require the secpath, so it should not be needed anymore.
However, in some of those places, the MPTCP extension has just been attached to the skb, so we cannot
simply drop all extensions. (CVE-2025-21864)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18244.291.73 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451002

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-21864

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 3/12/2025

Reference Information

CVE: CVE-2025-21864