Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.382.49

medium Tenable Self-Hosted Container Security Plugin ID 452270

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: genirq/msi: Store the IOMMU IOVA
directly in msi_desc instead of iommu_cookie The IOMMU translation for MSI message addresses has been a
2-step process, separated in time: 1) iommu_dma_prepare_msi(): A cookie pointer containing the IOVA
address is stored in the MSI descriptor when an MSI interrupt is allocated. 2)
iommu_dma_compose_msi_msg(): this cookie pointer is used to compute a translated message address. This has
an inherent lifetime problem for the pointer stored in the cookie that must remain valid between the two
steps. However, there is no locking at the irq layer that helps protect the lifetime. Today, this works
under the assumption that the iommu domain is not changed while MSI interrupts being programmed. This is
true for normal DMA API users within the kernel, as the iommu domain is attached before the driver is
probed and cannot be changed while a driver is attached. Classic VFIO type1 also prevented changing the
iommu domain while VFIO was running as it does not support changing the "container" after starting up.
However, iommufd has improved this so that the iommu domain can be changed during VFIO operation. This
potentially allows userspace to directly race VFIO_DEVICE_ATTACH_IOMMUFD_PT (which calls
iommu_attach_group()) and VFIO_DEVICE_SET_IRQS (which calls into iommu_dma_compose_msi_msg()). This
potentially causes both the cookie pointer and the unlocked call to iommu_get_domain_for_dev() on the MSI
translation path to become UAFs. Fix the MSI cookie UAF by removing the cookie pointer. The translated
IOVA address is already known during iommu_dma_prepare_msi() and cannot change. Thus, it can simply be
stored as an integer in the MSI descriptor. The other UAF related to iommu_get_domain_for_dev() will be
addressed in patch "iommu: Make iommu_dma_prepare_msi() into a generic operation" by using the IOMMU group
mutex. (CVE-2025-38062)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.382.49 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 452270

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.36

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-38062

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/12/2025

Reference Information

CVE: CVE-2025-38062