Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.613.56

high Tenable Self-Hosted Container Security Plugin ID 466582

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is
hashed in io_wq_remove_pending() io_wq_remove_pending() needs to fix up wq->hash_tail[] if the cancelled
work was the tail of its hash bucket. When doing this, it checks whether the preceding entry in
acct->work_list has the same hash value, but never checks that the predecessor is hashed at all.
io_get_work_hash() is simply atomic_read(&work->flags) >> IO_WQ_HASH_SHIFT, and the hash bits are never
set for non-hashed work, so it returns 0. Thus, when a hashed bucket-0 work is cancelled while a non-
hashed work is its list predecessor, the check spuriously passes and a pointer to the non-hashed io_kiocb
is stored in wq->hash_tail[0]. Because non-hashed work is dequeued via the fast path in
io_get_next_work(), which never touches hash_tail[], the stale pointer is never cleared. Therefore, after
the non-hashed io_kiocb completes and is freed back to req_cachep, wq->hash_tail[0] is a dangling pointer.
The io_wq is per-task (tctx->io_wq) and survives ring open/close, so the dangling pointer persists for the
lifetime of the task; the next hashed bucket-0 enqueue dereferences it in io_wq_insert_work() and
wq_list_add_after() writes through freed memory. Add the missing io_wq_is_hashed() check so a non-hashed
predecessor never inherits a hash_tail[] slot. (CVE-2026-46274)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.613.56 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466582

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.47

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-46274

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/8/2026

Reference Information

CVE: CVE-2026-46274