Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.528.3

high Tenable Self-Hosted Container Security Plugin ID 467356

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP
rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind
skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is
addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking
skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would
reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender
hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to
skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only
safely reads the ARP header; it does not make the later sender hardware address range writable. If that
range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits()
maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable
before reading the ARP header and before calling skb_store_bits(). (CVE-2026-53266)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.528.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467356

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Critical

Score: 9.3

Percentile: 99.82

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53266

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 6/25/2026

CISA Known Exploited Vulnerability Due Dates: 9/21/2026

Reference Information

CVE: CVE-2026-53266