Google: sys-kernel/lakitu-kernel-6_1: security update to 17800.436.42

high Tenable Self-Hosted Container Security Plugin ID 452533

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: hrtimers: Handle CPU state correctly
on hotplug Consider a scenario where a CPU transitions from CPUHP_ONLINE to halfway through a CPU
hotunplug down to CPUHP_HRTIMERS_PREPARE, and then back to CPUHP_ONLINE: Since hrtimers_prepare_cpu() does
not run, cpu_base.hres_active remains set to 1 throughout. However, during a CPU unplug operation, the
tick and the clockevents are shut down at CPUHP_AP_TICK_DYING. On return to the online state, for instance
CFS incorrectly assumes that the hrtick is already active, and the chance of the clockevent device to
transition to oneshot mode is also lost forever for the CPU, unless it goes back to a lower state than
CPUHP_HRTIMERS_PREPARE once. This round-trip reveals another issue; cpu_base.online is not set to 1 after
the transition, which appears as a WARN_ON_ONCE in enqueue_hrtimer(). Aside of that, the bulk of the per
CPU state is not reset either, which means there are dangling pointers in the worst case. Address this by
adding a corresponding startup() callback, which resets the stale per CPU state and sets the online flag.
[ tglx: Make the new callback unconditionally available, remove the online modification in the prepare()
callback and clear the remaining state in the starting callback instead of the prepare callback ]
(CVE-2024-57951)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 17800.436.42 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-109.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 452533

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.97

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-57951

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2024-57951