Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.85.5

medium Tenable Self-Hosted Container Security Plugin ID 451871

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: tcp: properly terminate timers for
kernel sockets We had various syzbot reports about tcp timers firing after the corresponding netns has
been dismantled. Fortunately Josef Bacik could trigger the issue more often, and could test a patch I
wrote two years ago. When TCP sockets are closed, we call inet_csk_clear_xmit_timers() to 'stop' the
timers. inet_csk_clear_xmit_timers() can be called from any context, including when socket lock is held.
This is the reason it uses sk_stop_timer(), aka del_timer(). This means that ongoing timers might finish
much later. For user sockets, this is fine because each running timer holds a reference on the socket, and
the user socket holds a reference on the netns. For kernel sockets, we risk that the netns is freed before
timer can complete, because kernel sockets do not hold reference on the netns. This patch adds
inet_csk_clear_xmit_timers_sync() function that using sk_stop_timer_sync() to make sure all timers are
terminated before the kernel socket is released. Modules using kernel sockets close them in their netns
exit() handler. Also add sock_not_owned_by_me() helper to get LOCKDEP support :
inet_csk_clear_xmit_timers_sync() must not be called while socket lock is held. It is very possible we can
revert in the future commit 3a58f13a881e ("net: rds: acquire refcount on TCP sockets") which attempted to
solve the issue in rds only. (net/smc/af_smc.c and net/mptcp/subflow.c have similar code) We probably can
remove the check_net() tests from tcp_out_of_resources() and __tcp_close() in the future. (CVE-2024-35910)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.85.5 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451871

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

Percentile: 96.73

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:P/A:C

CVSS Score Source: CVE-2024-35910

CVSS v3

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 5.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/12/2023

Reference Information

CVE: CVE-2024-35910