Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.731.2

high Tenable Self-Hosted Container Security Plugin ID 466751

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Repost Receive buffers for
malformed replies rpcrdma_wc_receive() decrements the transport's Receive count for every completion
before it dispatches a successful Receive to rpcrdma_reply_handler(). The handler must post a replacement
Receive WR before returning unless ownership of the rep has moved elsewhere, as on the backchannel path.
Commit 2ae50ad68cd7 ("xprtrdma: Close window between waking RPC senders and posting Receives") moved the
Receive refill out of rpcrdma_wc_receive(), where it had run ahead of every reply, into
rpcrdma_reply_handler() so that the responder's credit grant could be parsed before reposting. The bad-
version and short-reply exits never reach that refill: they recycle the rep and return without calling
rpcrdma_post_recvs(). A remote peer can therefore drain the client's posted Receive queue by sending a
sustained stream of replies that are shorter than the fixed transport header or that carry an unrecognized
RPC/RDMA version. Each such reply consumes one posted Receive without replacing it. Once the queue
empties, the peer's next Send finds no posted Receive and the transport stalls until reconnect. Route both
malformed-reply exits through the shared repost tail after recycling the rep, refilling against
buf->rb_credits, the most recent accepted credit grant. Neither exit updates the congestion window, so
RPCs admitted under the previous grant remain in flight awaiting replies. A smaller refill target would
let a stream of malformed replies ratchet the posted Receive count down to the batch floor while the
congestion window still admits rb_credits RPCs; a burst of valid replies to those RPCs could then overrun
the posted Receives, and because the client connects with rnr_retry_count of zero, a single RNR NAK
terminates the connection. Refilling against rb_credits also restores the target that applied to malformed
replies before commit 2ae50ad68cd7 ("xprtrdma: Close window between waking RPC senders and posting
Receives") when rpcrdma_post_recvs() computed it from rb_credits internally. rb_credits is at least one
from connection establishment onward, so the repost path always keeps Receives posted. (CVE-2026-72464)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.731.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466751

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.58

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-72464

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-72464