Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.439.45

medium Tenable Self-Hosted Container Security Plugin ID 466226

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: cpufreq: intel_pstate: Fix object
lifecycle issue in update_qos_request() The cpufreq_cpu_put() call in update_qos_request() takes place too
early because the latter subsequently calls freq_qos_update_request() that indirectly accesses the policy
object in question through the QoS request object passed to it. Fortunately, update_qos_request() is
called under intel_pstate_driver_lock, so this issue does not matter for changing the intel_pstate
operation mode, but it theoretically can cause a crash to occur on CPU device hot removal (which currently
can only happen in virt, but it is formally supported nevertheless). Address this issue by modifying
update_qos_request() to drop the reference to the policy later. (CVE-2025-40194)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.439.45 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 466226

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.44

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:P/A:C

CVSS Score Source: CVE-2025-40194

CVSS v3

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 5.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/23/2025

Reference Information

CVE: CVE-2025-40194