Google: sys-kernel/csql-kernel-6_1: security update to 18244.521.98

medium Tenable Self-Hosted Container Security Plugin ID 451209

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in
skb_segment_list for GRO packets When skb_segment_list() is called during packet forwarding, it handles
packets that were aggregated by the GRO engine. Historically, the segmentation logic in skb_segment_list
assumes that individual segments are split from a parent SKB and may need to carry their own socket memory
accounting. Accordingly, the code transfers truesize from the parent to the newly created segments. Prior
to commit ed4cccef64c1 ("gro: fix ownership transfer"), this truesize subtraction in skb_segment_list()
was valid because fragments still carry a reference to the original socket. However, commit ed4cccef64c1
("gro: fix ownership transfer") changed this behavior by ensuring that fraglist entries are explicitly
orphaned (skb->sk = NULL) to prevent illegal orphaning later in the stack. This change meant that the
entire socket memory charge remained with the head SKB, but the corresponding accounting logic in
skb_segment_list() was never updated. As a result, the current code unconditionally adds each fragment's
truesize to delta_truesize and subtracts it from the parent SKB. Since the fragments are no longer charged
to the socket, this subtraction results in an effective under-count of memory when the head is freed. This
causes sk_wmem_alloc to remain non-zero, preventing socket destruction and leading to a persistent memory
leak. The leak can be observed via KMEMLEAK when tearing down the networking environment: unreferenced
object 0xffff8881e6eb9100 (size 2048): comm "ping", pid 6720, jiffies 4295492526 backtrace:
kmem_cache_alloc_noprof+0x5c6/0x800 sk_prot_alloc+0x5b/0x220 sk_alloc+0x35/0xa00
inet6_create.part.0+0x303/0x10d0 __sock_create+0x248/0x640 __sys_socket+0x11b/0x1d0 Since
skb_segment_list() is exclusively used for SKB_GSO_FRAGLIST packets constructed by GRO, the truesize
adjustment is removed. The call to skb_release_head_state() must be preserved. As documented in commit
cf673ed0e057 ("net: fix fraglist segmentation reference count leak"), it is still required to correctly
drop references to SKB extensions that may be overwritten during __copy_skb_header(). (CVE-2026-22979)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.521.98 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451209

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.64

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-22979

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/23/2026

Reference Information

CVE: CVE-2026-22979