Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.584.3

high Tenable Self-Hosted Container Security Plugin ID 467458

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: remove CAP_SYS_RAWIO zero-padding
in dev_validate_header dev_validate_header() reads dev->hard_header_len directly when zero-padding short
link layer headers for CAP_SYS_RAWIO holders: if (capable(CAP_SYS_RAWIO)) { memset(ll_header + len, 0,
dev->hard_header_len - len); return true; } Packet send paths call dev_validate_header() on skbs whose
headroom was allocated from an earlier hard_header_len read. If the device is reconfigured so that
dev->hard_header_len increases before validation, the memset writes past the reserved buffer, an out-of-
bounds write. This out-of-bounds write is masked in some SOCK_RAW paths today because the same concurrent
increase can first make skb_push() exceed the reserved headroom and trigger skb_under_panic(). Remove the
zero-padding branch before making those hard_header_len reads consistent, so the snapshot fixes do not
turn a loud panic into a silent overwrite. This path is only reached for variable length L2 protocols,
where len < hard_header_len but len >= min_header_len. No remaining in-tree variable length L2 protocol
implements header_ops->validate, and the CAP_SYS_RAWIO bypass that zero-pads and accepts short headers has
no real value beyond allowing testing of intentionally malformed input. Drop the CAP_SYS_RAWIO branch. The
remaining reads of dev->hard_header_len in dev_validate_header() are comparisons only and have no memory
safety impact. (CVE-2026-80731)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.584.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467458

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.22

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-80731

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/31/2026

Reference Information

CVE: CVE-2026-80731