Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.700.7

high Tenable Self-Hosted Container Security Plugin ID 468476

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix integer overflow in MFT
cluster validation In ntfs_init_from_boot(), the boot sector's MFT cluster numbers are validated against
the volume size with: if (mlcn * sct_per_clst >= sectors || mlcn2 * sct_per_clst >= sectors) goto out;
mlcn and mlcn2 are u64 fields read directly from the boot sector. sct_per_clst is bounded above by 4096
(true_sectors_per_clst() plus the is_power_of_2() check below it), but the multiplication is done in u64
and wraps when mlcn (or mlcn2) is large enough -- e.g. mlcn near 2^62 with sct_per_clst == 4 wraps to 0,
which compares below any non-zero 'sectors', so the check is bypassed and the malformed record is
accepted. The accepted mlcn is then used unchanged in sbi->mft.lbo = mlcn << cluster_bits; In practice the
resulting reads fail at the block layer (sb_bread() returns NULL via grow_buffers()'s check_mul_overflow()
guard), so today this manifests as mount failing in odd places rather than as something more dangerous,
but the validation step is still wrong and there is no reason for callers to rely on the block layer to
catch a value that should never have been accepted in the first place. Use check_mul_overflow() to compute
the two sector positions and fail the mount if either multiplication wraps; this preserves the existing
semantics (mlcn * sct_per_clst >= sectors) instead of switching to division (mlcn >= sectors /
sct_per_clst), which would tighten the check at edge cases where 'sectors' is not a multiple of
sct_per_clst. The check_*_overflow() style is the one ntfs3 already uses for similar on-disk arithmetic in
fs/ntfs3/run.c. (CVE-2026-90200)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.700.7 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 468476

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.41

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-90200

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/17/2026

Reference Information

CVE: CVE-2026-90200