Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.731.2

high Tenable Self-Hosted Container Security Plugin ID 466102

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Fix effective prog array index
with BPF_F_PREORDER replace_effective_prog() and purge_effective_progs() located the slot in the effective
array by walking the program hlist and counting entries linearly. That count does not match the array
layout: compute_effective_ progs() places BPF_F_PREORDER programs at the front (ancestor cgroup first,
attach order within a cgroup) and the rest after them (descendant cgroup first). So when a preorder
program is present, the linear hlist position no longer equals the program's index in the effective array.
For replace_effective_prog() (bpf_link_update()) this overwrote the wrong slot, corrupting the effective
order. For purge_effective_progs(), it could dummy out a slot belonging to a different program and leave
the detached program in the array while bpf_prog_put() drops its reference, i.e. a use-after-free. Fix
both by replaying compute_effective_progs()'s placement (including the per-cgroup preorder reversal) in a
shared effective_prog_pos() helper. Identify the entry by its struct bpf_prog_list pointer rather than by
(prog, link) value, so the lookup resolves to exactly the attachment the syscall selected even when the
same bpf_prog is attached to several cgroups in the hierarchy. (CVE-2026-72427)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18613.731.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466102

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.77

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-72427

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-72427