Google: sys-kernel/csql-kernel-6_1, sys-kernel/tpusev-kernel-6_6: security update to 18613.534.62

high Tenable Self-Hosted Container Security Plugin ID 466071

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix possible invalid
rdp's->nocb_cb_kthread pointer access In the preparation stage of CPU online, if the corresponding the
rdp's->nocb_cb_kthread does not exist, will be created, there is a situation where the rdp's rcuop
kthreads creation fails, and then de-offload this CPU's rdp, does not assign this CPU's
rdp->nocb_cb_kthread pointer, but this rdp's->nocb_gp_rdp and rdp's->rdp_gp->nocb_gp_kthread is still
valid. This will cause the subsequent re-offload operation of this offline CPU, which will pass the
conditional check and the kthread_unpark() will access invalid rdp's->nocb_cb_kthread pointer. This commit
therefore use rdp's->nocb_gp_kthread instead of rdp_gp's->nocb_gp_kthread for safety check.
(CVE-2025-38704)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.534.62 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466071

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-38704

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/4/2025

Reference Information

CVE: CVE-2025-38704