Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.700.7

critical Tenable Self-Hosted Container Security Plugin ID 468329

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: sunrpc: xprtsock: annotate shared
socket callbacks with READ_ONCE/WRITE_ONCE xprtsock replaces and restores sk->sk_data_ready and
sk->sk_write_space on live sockets with plain stores, and xs_udp_do_set_buffer_size() invokes
sk->sk_write_space via a plain load. These callback pointers are shared with generic socket and protocol
paths that may read or invoke them concurrently, so xprtsock needs the same READ_ONCE()/WRITE_ONCE()
callback visibility contract that the validated 4022 family applied elsewhere. When SUNRPC takes over an
AF_LOCAL, UDP, or TCP socket and later restores the lower-socket callbacks during teardown, another CPU
may still hold an earlier callback snapshot. The plain replace/restore pattern leaves the same visibility
hole as the validated 4022 family, so a stale snapshot can still invoke xs_data_ready() or
xs_udp_write_space() after the live callback fields have already been restored to the lower-socket
handlers. Use WRITE_ONCE() for the shared sk_data_ready and sk_write_space stores in
xs_local_finish_connecting(), xs_udp_finish_connecting(), xs_tcp_finish_connecting(), and
xs_restore_old_callbacks(). Use READ_ONCE() for the direct sk_write_space invocation in
xs_udp_do_set_buffer_size(). This matches the required callback visibility contract while leaving adjacent
sk_state_change and sk_error_report handling unchanged. (CVE-2026-90235)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.700.7 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 468329

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.27

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-90235

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/17/2026

Reference Information

CVE: CVE-2026-90235