Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.613.56

high Tenable Self-Hosted Container Security Plugin ID 466563

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE
continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge
CE record and passes it to sb_bread() without checking that the block number is within the mounted ISO
9660 volume. commit e595447e177b ("[PATCH] rock.c: handle corrupted directories") added cont_offset and
cont_size rejection for the CE continuation but did not validate the extent block number itself. commit
f54e18f1b831 ("isofs: Fix infinite looping over CE entries") later capped the CE chain length at
RR_MAX_CE_ENTRIES = 32 but again left the block number unchecked. With a crafted ISO mounted via udisks2
(desktop optical auto-mount) or via CAP_SYS_ADMIN mount, rs->cont_extent can therefore point at an out-of-
range block or at blocks belonging to an adjacent filesystem on the same block device. sb_bread() on an
out-of-range block returns NULL cleanly via the block layer EIO path, so there is no memory-safety
violation. For in-range reads of adjacent- filesystem data, the CE buffer is parsed as Rock Ridge records
and only the text of SL sub-records reaches userspace through readlink(), which makes the info-leak
channel narrow and difficult to exploit; still, rejecting the malformed CE outright matches the rejection
shape already present in the same function for cont_offset and cont_size. Add an ISOFS_SB(sb)->s_nzones
bounds check to rock_continue() next to the existing offset/size rejection, printing the same corrupted-
directory-entry notice. (CVE-2026-46303)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.613.56 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466563

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 96

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:P/A:N

CVSS Score Source: CVE-2026-46303

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/26/2026

Reference Information

CVE: CVE-2026-46303