Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.731.2

high Tenable Self-Hosted Container Security Plugin ID 465987

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: fix UAF by restoring RCU-delayed
inode freeing in bpffs commit 4f375ade6aa9 ("bpf: Avoid RCU context warning when unpinning htab with
internal structs") moved inode cleanup from ->free_inode() into ->destroy_inode() to avoid sleeping in RCU
context when calling bpf_any_put(). However this removed the RCU delay on freeing the inode itself and the
cached symlink body (i_link), both of which can be accessed by RCU pathwalk (pick_link, may_lookup etc.).
This causes a use-after-free when a concurrent unlinkat() drops the last inode reference and
destroy_inode() frees the inode immediately, while another task is still walking the path in RCU mode and
reads inode->i_opflags (offset +2) inside current_time() -> is_mgtime(). KASAN reports: BUG: KASAN: slab-
use-after-free in is_mgtime include/linux/fs.h:2313 Read of size 2 at addr ffff8880407e4282 (offset +2 =
i_opflags) The rules (per Al Viro): ->destroy_inode() called immediately, can sleep, use for blocking
cleanup e.g. bpf_any_put() ->free_inode() called after RCU grace period, use for freeing inode and
anything RCU-accessible e.g. i_link Fix: split the two concerns properly: - keep bpf_any_put() in
bpf_destroy_inode() since it is blocking and needs to run promptly - introduce bpf_free_inode() to handle
kfree(i_link) and free_inode_nonrcu() with proper RCU delay, preventing the UAF (CVE-2026-74363)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18613.731.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 465987

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.19

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74363

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-74363