Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.37

high Tenable Self-Hosted Container Security Plugin ID 466076

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink
components to the SL record get_symlink_chunk() and the SL handling in parse_rock_ridge_inode_internal()
walk the variable-length components of a Rock Ridge "SL" (symbolic link) record. Each component is a two-
byte header (flags, len) followed by len bytes of text, so it occupies slp->len + 2 bytes. Both loops read
slp->len and advance to the next component, and get_symlink_chunk() additionally does memcpy(rpnt,
slp->text, slp->len), but neither checks that the component lies within the SL record before dereferencing
it. A crafted SL record whose component declares a len that runs past the record (rr->len) therefore
triggers an out-of-bounds read of up to 255 bytes. When the record sits at the tail of its backing buffer
- for example a small kmalloc()ed continuation block reached through a CE record - the read crosses the
allocation; get_symlink_chunk() then copies the out-of-bounds bytes into the symlink body returned to user
space by readlink(), disclosing adjacent kernel memory. ISO 9660 images are routinely mounted from
untrusted removable media - desktop environments auto-mount them (e.g. via udisks2) without CAP_SYS_ADMIN
- so the record contents are attacker-controlled. Reject any component that does not fit in the remaining
record bytes before using it. In get_symlink_chunk() return NULL, like the existing output-buffer (plimit)
checks, so a malformed record makes readlink() fail with -EIO rather than silently returning a truncated
target; in parse_rock_ridge_inode_internal() stop the inode-size walk. (CVE-2026-64317)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.675.37 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466076

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.16

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-64317

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/23/2026

Reference Information

CVE: CVE-2026-64317