Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.521.65

high Tenable Self-Hosted Container Security Plugin ID 451150

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ipv4: route: Prevent
rt_bind_exception() from rebinding stale fnhe The sit driver's packet transmission path calls:
sit_tunnel_xmit() -> update_or_create_fnhe(), which lead to fnhe_remove_oldest() being called to delete
entries exceeding FNHE_RECLAIM_DEPTH+random. The race window is between fnhe_remove_oldest() selecting
fnheX for deletion and the subsequent kfree_rcu(). During this time, the concurrent path's
__mkroute_output() -> find_exception() can fetch the soon-to-be-deleted fnheX, and rt_bind_exception()
then binds it with a new dst using a dst_hold(). When the original fnheX is freed via RCU, the dst
reference remains permanently leaked. CPU 0 CPU 1 __mkroute_output() find_exception() [fnheX]
update_or_create_fnhe() fnhe_remove_oldest() [fnheX] rt_bind_exception() [bind dst] RCU callback [fnheX
freed, dst leak] This issue manifests as a device reference count leak and a warning in dmesg when
unregistering the net device: unregister_netdevice: waiting for sitX to become free. Usage count = N Ido
Schimmel provided the simple test validation method [1]. The fix clears 'oldest->fnhe_daddr' before
calling fnhe_flush_routes(). Since rt_bind_exception() checks this field, setting it to zero prevents the
stale fnhe from being reused and bound to a new dst just before it is freed. [1] ip netns add ns1 ip -n
ns1 link set dev lo up ip -n ns1 address add 192.0.2.1/32 dev lo ip -n ns1 link add name dummy1 up type
dummy ip -n ns1 route add 192.0.2.2/32 dev dummy1 ip -n ns1 link add name gretap1 up arp off type gretap \
local 192.0.2.1 remote 192.0.2.2 ip -n ns1 route add 198.51.0.0/16 dev gretap1 taskset -c 0 ip netns exec
ns1 mausezahn gretap1 \ -A 198.51.100.1 -B 198.51.0.0/16 -t udp -p 1000 -c 0 -q & taskset -c 2 ip netns
exec ns1 mausezahn gretap1 \ -A 198.51.100.1 -B 198.51.0.0/16 -t udp -p 1000 -c 0 -q & sleep 10 ip netns
pids ns1 | xargs kill ip netns del ns1 (CVE-2025-68241)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.521.65 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 451150

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.4

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-68241

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/9/2025

Reference Information

CVE: CVE-2025-68241