Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.37

critical Tenable Self-Hosted Container Security Plugin ID 466311

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in
devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that
clone path copies only the linear xdp_frame data, while fragmented frames keep skb_shared_info in tailroom
outside the linear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but without valid frag
metadata, and the later free path can interpret uninitialized tail data as skb_shared_info, leading to an
out-of-bounds access during frame return. Reject fragmented native XDP frames in dev_map_enqueue_clone().
Add the same restriction to the generic XDP clone path in dev_map_redirect_clone(). Generic XDP represents
fragmented packets as nonlinear skbs, and rejecting them here keeps clone-based broadcast support aligned
between native and generic XDP. (CVE-2026-64355)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.675.37 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 466311

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.28

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64355

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/23/2026

Reference Information

CVE: CVE-2026-64355