Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.731.2

critical Tenable Self-Hosted Container Security Plugin ID 465670

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when
releasing a never added disk disk_release() undoes blk_mq_init_allocated_queue() for a disk whose probe
failed before add_disk(), but it only calls blk_mq_exit_queue(). Nothing there stops q->timeout, and that
timer rolls forward: it stays pending until it next expires, not until the last request completes. So if
the driver issued any I/O before adding the disk, the request_queue is freed while still linked into a
timer wheel bucket. Commit 6f8191fdf41d ("block: simplify disk shutdown") dropped the blk_cleanup_queue()
call that used to stop it. __del_gendisk() and blk_mq_destroy_queue() still do; only the probe failure
path lost it. nvme gets there because nvme_update_ns_info() submits Report Zones or FDP io-mgmt-recv on
ns->queue before the disk is added, so a later failure - a concurrent reset setting NVME_CTRL_FROZEN, or
device_add_disk() failing - lands in put_disk() with the timer armed: BUG: KASAN: slab-use-after-free in
detach_if_pending+0x30c/0x340 Write of size 8 at addr ffff888004d71310 by task kworker/u8:2/37
__timer_delete_sync+0x156/0x240 kernel/time/timer.c:1621 blk_sync_queue+0x22/0x40 block/blk-core.c:222
nvme_sync_queues+0x100/0x150 drivers/nvme/host/core.c:5362 nvme_reset_work+0x138/0x930
drivers/nvme/host/pci.c:3264 Allocated by task 34: __blk_mq_alloc_disk+0x33/0x100 block/blk-mq.c:4462
nvme_alloc_ns+0x290/0x3870 drivers/nvme/host/core.c:4146 Freed by task 0: blk_free_queue_rcu+0x3a/0x50
block/blk-core.c:254 rcu_core+0xc10/0x1730 kernel/rcu/tree.c:2857 The queue being synced there is
ctrl->admin_q, only a victim sharing a timer wheel bucket with the freed queue's dangling entry; other
runs tripped in enqueue_timer(), __run_timers() or blk_mq_timeout_work(). Failing nvme_alloc_ns() with a
debug patch makes it deterministic: one leaked timer trips KASAN within seconds, while 1987 patched
releases produced no splat. Stop the timer and the queue work items before blk_mq_exit_queue(), like
blk_mq_destroy_queue() does. Found by FuzzNvme. (CVE-2026-80589)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.731.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 465670

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.18

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-80589

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/26/2026

Reference Information

CVE: CVE-2026-80589