Google: sys-kernel/csql-kernel-6_6: security update to 19165.0.0

medium Tenable Self-Hosted Container Security Plugin ID 452452

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Mark raw_tp arguments with
PTR_MAYBE_NULL Arguments to a raw tracepoint are tagged as trusted, which carries the semantics that the
pointer will be non-NULL. However, in certain cases, a raw tracepoint argument may end up being NULL. More
context about this issue is available in [0]. Thus, there is a discrepancy between the reality, that
raw_tp arguments can actually be NULL, and the verifier's knowledge, that they are never NULL, causing
explicit NULL checks to be deleted, and accesses to such pointers potentially crashing the kernel. To fix
this, mark raw_tp arguments as PTR_MAYBE_NULL, and then special case the dereference and pointer
arithmetic to permit it, and allow passing them into helpers/kfuncs; these exceptions are made for raw_tp
programs only. Ensure that we don't do this when ref_obj_id > 0, as in that case this is an acquired
object and doesn't need such adjustment. The reason we do mask_raw_tp_trusted_reg logic is because other
will recheck in places whether the register is a trusted_reg, and then consider our register as untrusted
when detecting the presence of the PTR_MAYBE_NULL flag. To allow safe dereference, we enable PROBE_MEM
marking when we see loads into trusted pointers with PTR_MAYBE_NULL. While trusted raw_tp arguments can
also be passed into helpers or kfuncs where such broken assumption may cause issues, a future patch set
will tackle their case separately, as PTR_TO_BTF_ID (without PTR_TRUSTED) can already be passed into
helpers and causes similar problems. Thus, they are left alone for now. It is possible that these checks
also permit passing non-raw_tp args that are trusted PTR_TO_BTF_ID with null marking. In such a case,
allowing dereference when pointer is NULL expands allowed behavior, so won't regress existing programs,
and the case of passing these into helpers is the same as above and will be dealt with later. Also update
the failure case in tp_btf_nullable selftest to capture the new behavior, as the verifier will no longer
cause an error when directly dereference a raw tracepoint argument marked as __nullable. [0]:
https://lore.kernel.org/bpf/[email protected] (CVE-2024-56702)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 19165.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 452452

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-56702

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/28/2024

Reference Information

CVE: CVE-2024-56702