Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.613.40

medium Tenable Self-Hosted Container Security Plugin ID 466735

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfilter: arp_tables: fix IEEE1394
ARP payload parsing Weiming Shi says: "arp_packet_match() unconditionally parses the ARP payload assuming
two hardware addresses are present (source and target). However, IPv4-over-IEEE1394 ARP (RFC 2734) omits
the target hardware address field, and arp_hdr_len() already accounts for this by returning a shorter
length for ARPHRD_IEEE1394 devices. As a result, on IEEE1394 interfaces arp_packet_match() advances past a
nonexistent target hardware address and reads the wrong bytes for both the target device address
comparison and the target IP address. This causes arptables rules to match against garbage data, leading
to incorrect filtering decisions: packets that should be accepted may be dropped and vice versa. The ARP
stack in net/ipv4/arp.c (arp_create and arp_process) already handles this correctly by skipping the target
hardware address for ARPHRD_IEEE1394. Apply the same pattern to arp_packet_match()." Mangle the original
patch to always return 0 (no match) in case user matches on the target hardware address which is never
present in IEEE1394. Note that this returns 0 (no match) for either normal and inverse match because
matching in the target hardware address in ARPHRD_IEEE1394 has never been supported by arptables. This is
intentional, matching on the target hardware address should never evaluate true for ARPHRD_IEEE1394.
Moreover, adjust arpt_mangle to drop the packet too as AI suggests: In arpt_mangle, the logic assumes a
standard ARP layout. Because IEEE1394 (FireWire) omits the target hardware address, the linear pointer
arithmetic miscalculates the offset for the target IP address. This causes mangling operations to write to
the wrong location, leading to packet corruption. To ensure safety, this patch drops packets (NF_DROP)
when mangling is requested for these fields on IEEE1394 devices, as the current implementation cannot
correctly map the FireWire ARP payload. This omits both mangling target hardware and IP address. Even if
IP address mangling should be possible in IEEE1394, this would require to adjust arpt_mangle offset
calculation, which has never been supported. Based on patch from Weiming Shi <[email protected]>.
(CVE-2026-45844)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.613.40 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 466735

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.71

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-45844

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/27/2026

Reference Information

CVE: CVE-2026-45844