Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.439.16

medium Tenable Self-Hosted Container Security Plugin ID 466156

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: Squashfs: fix uninit-value in
squashfs_get_parent Syzkaller reports a "KMSAN: uninit-value in squashfs_get_parent" bug. This is caused
by open_by_handle_at() being called with a file handle containing an invalid parent inode number. In
particular the inode number is that of a symbolic link, rather than a directory. Squashfs_get_parent()
gets called with that symbolic link inode, and accesses the parent member field. unsigned int parent_ino =
squashfs_i(inode)->parent; Because non-directory inodes in Squashfs do not have a parent value, this is
uninitialised, and this causes an uninitialised value access. The fix is to initialise parent with the
invalid inode 0, which will cause an EINVAL error to be returned. Regular inodes used to share the parent
field with the block_list_start field. This is removed in this commit to enable the parent field to
contain the invalid inode number 0. (CVE-2025-40049)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.439.16 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 466156

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.8

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:N/A:C

CVSS Score Source: CVE-2025-40049

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/23/2025

Reference Information

CVE: CVE-2025-40049