Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.64

high Tenable Self-Hosted Container Security Plugin ID 465887

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix source list corruption
on a failed replace When replacing the source list of an MDB remote entry, all existing sources are first
marked for deletion and vxlan_mdb_remote_srcs_add() is then called to add the new source list. Sources
present in the new list have their deletion mark cleared, and any sources left marked afterwards are
removed. If vxlan_mdb_remote_srcs_add() fails partway through, its error path deletes all entries on the
remote's source list. That rollback is only correct for its other caller, vxlan_mdb_remote_add(), where
the remote was just allocated and the list contains solely entries added during the call. On the replace
path the list also holds pre-existing sources, so a failed replace tears them down together with their (S,
G) forwarding entries instead of leaving the entry unchanged. This is reachable from an existing (*, G)
remote. An EXCLUDE filter that loses sources starts forwarding traffic that should be blocked, while an
INCLUDE filter that loses sources drops traffic that should be forwarded. Mark entries created during the
current pass with a new VXLAN_SGRP_F_NEW flag. On failure, delete only those entries and clear the
deletion mark on the pre-existing ones, so a failed replace leaves the source list untouched. Retain the
flag until the whole operation succeeds and then clear it. Also stop vxlan_mdb_remote_src_add() from
deleting a pre-existing entry it only looked up when adding that entry's forwarding entry fails.
(CVE-2026-68116)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18613.675.64 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 465887

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

Percentile: 57.58

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2026-68116

CVSS v3

Risk Factor: High

Base Score: 7.9

Temporal Score: 6.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/10/2026

Reference Information

CVE: CVE-2026-68116