Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.439.108

medium Tenable Self-Hosted Container Security Plugin ID 465828

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Don't skip unrelated
instruction if INT3/INTO is replaced When re-injecting a soft interrupt from an INT3, INT0, or (select)
INTn instruction, discard the exception and retry the instruction if the code stream is changed (e.g. by a
different vCPU) between when the CPU executes the instruction and when KVM decodes the instruction to get
the next RIP. As effectively predicted by commit 6ef88d6e36c2 ("KVM: SVM: Re-inject INT3/INTO instead of
retrying the instruction"), failure to verify that the correct INTn instruction was decoded can
effectively clobber guest state due to decoding the wrong instruction and thus specifying the wrong next
RIP. The bug most often manifests as "Oops: int3" panics on static branch checks in Linux guests. Enabling
or disabling a static branch in Linux uses the kernel's "text poke" code patching mechanism. To modify
code while other CPUs may be executing that code, Linux (temporarily) replaces the first byte of the
original instruction with an int3 (opcode 0xcc), then patches in the new code stream except for the first
byte, and finally replaces the int3 with the first byte of the new code stream. If a CPU hits the int3,
i.e. executes the code while it's being modified, then the guest kernel must look up the RIP to determine
how to handle the #BP, e.g. by emulating the new instruction. If the RIP is incorrect, then this lookup
fails and the guest kernel panics. The bug reproduces almost instantly by hacking the guest kernel to
repeatedly check a static branch[1] while running a drgn script[2] on the host to constantly swap out the
memory containing the guest's TSS. [1]: https://gist.github.com/osandov/44d17c51c28c0ac998ea0334edf90b5a
[2]: https://gist.github.com/osandov/10e45e45afa29b11e0c7209247afc00b (CVE-2025-68259)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.439.108 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 465828

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.42

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-68259

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/16/2025

Reference Information

CVE: CVE-2025-68259