Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.584.3

high Tenable Self-Hosted Container Security Plugin ID 467341

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: don't leak
bad clone into future transaction On memory allocation failure the cloned nft_pipapo_match can enter a bad
state: - some fields can have their lookup tables resized while others did not - bits might have been
toggled - scratch map can be undersized which also means m->bsize_max can be lower than what is required
This means that the next insertion in the same batch can trigger out-of-bounds writes. Furthermore, a
failure in the first can result in the bad clone to leak into the next transaction because the abort
callback is never executed in this case (the upper layer saw an error and no attempt to allocate a
transactional request was made). Record a state for the nft_pipapo_match structure: - NEW (pristine clone)
- MOD (modified clone with good state) - ERR (potentially bogus content) Then make it so that deletes and
insertions fail when the clone entered ERR state. In case the very first insert attempt results in an
error, free the clone right away. (CVE-2026-72252)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.584.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467341

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.17

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-72252

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-72252