Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.2

high Tenable Self-Hosted Container Security Plugin ID 466269

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: check allocation
under invalidate lock commit 2d1f7b65f5de ("dm cache policy smq: fix missing locks in invalidating cache
blocks") added mq->lock around the destructive part of smq_invalidate_mapping(), but left the e->allocated
check outside the critical section. That leaves a check-then-act race. Two concurrent invalidators can
both observe e->allocated as true before either of them takes mq->lock. The first invalidator that
acquires the lock removes the entry from the queues and hash table and then calls free_entry(), which
clears e->allocated and puts the entry back on the free list. The second invalidator can then acquire
mq->lock and continue with the stale result of the unlocked check. This can corrupt the SMQ queues or hash
table by deleting an entry that is no longer on those structures. It can also hit the allocation check in
free_entry() when the same entry is freed again. Move the allocation check under mq->lock so the predicate
and the destructive operations are serialized by the same lock. (CVE-2026-53265)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18613.675.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466269

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.5

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53265

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/25/2026

Reference Information

CVE: CVE-2026-53265