Google: sys-kernel/lakitu-kernel-5_10: security update to 17033.0.0

medium Tenable Self-Hosted Container Security Plugin ID 452147

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ipv6: fix memory leak in
fib6_rule_suppress The kernel leaks memory when a `fib` rule is present in IPv6 nftables firewall rules
and a suppress_prefix rule is present in the IPv6 routing rules (used by certain tools such as wg-quick).
In such scenarios, every incoming packet will leak an allocation in `ip6_dst_cache` slab cache. After some
hours of `bpftrace`-ing and source code reading, I tracked down the issue to ca7a03c41753 ("ipv6: do not
free rt if FIB_LOOKUP_NOREF is set on suppress rule"). The problem with that change is that the generic
`args->flags` always have `FIB_LOOKUP_NOREF` set[1][2] but the IPv6-specific flag `RT6_LOOKUP_F_DST_NOREF`
might not be, leading to `fib6_rule_suppress` not decreasing the refcount when needed. How to reproduce: -
Add the following nftables rule to a prerouting chain: meta nfproto ipv6 fib saddr . mark . iif oif
missing drop This can be done with: sudo nft create table inet test sudo nft create chain inet test
test_chain '{ type filter hook prerouting priority filter + 10; policy accept; }' sudo nft add rule inet
test test_chain meta nfproto ipv6 fib saddr . mark . iif oif missing drop - Run: sudo ip -6 rule add table
main suppress_prefixlength 0 - Watch `sudo slabtop -o | grep ip6_dst_cache` to see memory usage increase
with every incoming ipv6 packet. This patch exposes the protocol-specific flags to the protocol specific
`suppress` function, and check the protocol-specific `flags` argument for RT6_LOOKUP_F_DST_NOREF instead
of the generic FIB_LOOKUP_NOREF when decreasing the refcount, like this. [1]:
https://github.com/torvalds/linux/blob/ca7a03c4175366a92cee0ccc4fec0038c3266e26/net/ipv6/fib6_rules.c#L71
[2]:
https://github.com/torvalds/linux/blob/ca7a03c4175366a92cee0ccc4fec0038c3266e26/net/ipv6/fib6_rules.c#L99
(CVE-2021-47546)

Solution

Update the sys-kernel/lakitu-kernel-5_10 library and its related packages to version 17033.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-101.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 452147

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2021-47546

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/21/2021

Reference Information

CVE: CVE-2021-47546