Google: sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6: security update to 18514.0.0

high Tenable Self-Hosted Container Security Plugin ID 466051

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: 9p: add missing locking around taking
dentry fid list Fix a use-after-free on dentry's d_fsdata fid list when a thread looks up a fid through
dentry while another thread unlinks it: UAF thread: refcount_t: addition on 0; use-after-free. p9_fid_get
linux/./include/net/9p/client.h:262 v9fs_fid_find+0x236/0x280 linux/fs/9p/fid.c:129
v9fs_fid_lookup_with_uid linux/fs/9p/fid.c:181 v9fs_fid_lookup+0xbf/0xc20 linux/fs/9p/fid.c:314
v9fs_vfs_getattr_dotl+0xf9/0x360 linux/fs/9p/vfs_inode_dotl.c:400 vfs_statx+0xdd/0x4d0 linux/fs/stat.c:248
Freed by: p9_fid_destroy (inlined) p9_client_clunk+0xb0/0xe0 linux/net/9p/client.c:1456 p9_fid_put
linux/./include/net/9p/client.h:278 v9fs_dentry_release+0xb5/0x140 linux/fs/9p/vfs_dentry.c:55
v9fs_remove+0x38f/0x620 linux/fs/9p/vfs_inode.c:518 vfs_unlink+0x29a/0x810 linux/fs/namei.c:4335 The
problem is that d_fsdata was not accessed under d_lock, because d_release() normally is only called once
the dentry is otherwise no longer accessible but since we also call it explicitly in v9fs_remove that lock
is required: move the hlist out of the dentry under lock then unref its fids once they are no longer
accessible. (CVE-2024-39463)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18514.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466051

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-39463

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/25/2024

Reference Information

CVE: CVE-2024-39463