Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.584.3

high Tenable Self-Hosted Container Security Plugin ID 467366

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache
on vring reconfiguration vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring metadata
region, and iotlb_access_ok() returns early on a cache hit, taking the hit as proof that the region has
already been validated: if (vhost_vq_meta_fetch(vq, addr, len, type)) return true; The cache is reset on
VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on device IOTLB (re)initialisation and on vq reset, but not
when VHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when VHOST_SET_VRING_NUM changes
the region sizes. With a device IOTLB attached both ioctls are accepted while the vq is live, and neither
validates the addresses at ioctl time: vq_access_ok() and vq_log_used_access_ok() return true early
because the addresses are GIOVAs, deferring validation to prefetch time. Once the cache has been populated
that deferred validation no longer runs -- vq_meta_prefetch() hits the stale entry and returns true -- and
vhost_vq_meta_fetch() keeps translating through the old mapping as map->addr + addr - map->start for an
address the mapping no longer covers. vhost_copy_to_user() and vhost_copy_from_user() consume the result
with __copy_to_user() and __copy_from_user(), which do not check it either, so a subsequent used ring
update or descriptor fetch accesses memory outside the region the IOTLB actually maps. Reset the metadata
cache whenever the vring is reconfigured, so the new addresses are pushed back through iotlb_access_ok()'s
slow path. (CVE-2026-74580)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.584.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467366

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.48

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74580

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/21/2026

Reference Information

CVE: CVE-2026-74580