Google: sys-kernel/csql-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.534.62

high Tenable Self-Hosted Container Security Plugin ID 466095

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in
init/destroy rollback asymmetry Fix a use-after-free in the clsact qdisc upon init/destroy rollback
asymmetry. The latter is achieved by first fully initializing a clsact instance, and then in a second step
having a replacement failure for the new clsact qdisc instance. clsact_init() initializes ingress first
and then takes care of the egress part. This can fail midway, for example, via tcf_block_get_ext(). Upon
failure, the kernel will trigger the clsact_destroy() callback. Commit 1cb6f0bae504 ("bpf: Fix too early
release of tcx_entry") details the way how the transition is happening. If tcf_block_get_ext on the
q->ingress_block ends up failing, we took the tcx_miniq_inc reference count on the ingress side, but not
yet on the egress side. clsact_destroy() tests whether the {ingress,egress}_entry was non-NULL. However,
even in midway failure on the replacement, both are in fact non-NULL with a valid egress_entry from the
previous clsact instance. What we really need to test for is whether the qdisc instance-specific ingress
or egress side previously got initialized. This adds a small helper for checking the miniq initialization
called mini_qdisc_pair_inited, and utilizes that upon clsact_destroy() in order to fix the use-after-free
scenario. Convert the ingress_destroy() side as well so both are consistent to each other.
(CVE-2026-23413)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18613.534.62 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466095

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.76

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-23413

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/2/2026

Reference Information

CVE: CVE-2026-23413