Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.700.7

medium Tenable Self-Hosted Container Security Plugin ID 468654

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: smb: client: fix request buffer leak
in smb2_new_read_req() smb2_new_read_req() allocates the request buffer with smb2_plain_req_init() but
only publishes it to the caller with *buf = req at the very end of the function. Two error returns sit in
between: rc = smb2_plain_req_init(SMB2_READ, io_parms->tcon, server, (void **) &req, total_len); if (rc)
return rc; if (server == NULL) return -ECONNABORTED; [...] rdata->mr = smbd_register_mr(server->smbd_conn,
&rdata->subreq.io_iter, true, need_invalidate); if (!rdata->mr) return -EAGAIN; On either of them the
buffer is neither released nor handed back, so it is leaked. The caller cannot clean up after it:
smb2_async_readv() does 'goto out' on a non-zero return, which skips the cifs_small_buf_release(buf) at
async_readv_out, and buf has not been assigned at that point in any case. The write path has never had
this problem. smb2_async_writev() registers the memory region inline and jumps to its release label
instead of returning: wdata->mr = smbd_register_mr(...); if (!wdata->mr) { rc = -EAGAIN; goto
async_writev_out; } Commit b7972092199f ("cifs: smbd: Retry on memory registration failure") changed both
sides from -ENOBUFS to -EAGAIN in a single patch, which puts the two shapes next to each other. Only the
-EAGAIN return is reachable in practice, because smb2_plain_req_init() calls smb2_reconnect() first and
that already fails with -EIO when server is NULL, before anything is allocated. Both returns are given the
same treatment here rather than leaving one of them correct only by accident. Because -EAGAIN is a
replayable error, the failure also reaches the retry block at the end of smb2_async_readv(), which marks
the subrequest NETFS_SREQ_NEED_RETRY, so a failing registration can be retried rather than ending the I/O,
and every attempt that reaches it leaks another buffer. smb2_should_replay() short-circuits on
tcon->retry, so on a hard mount the attempt count is not bounded by the retrans setting. Only the
asynchronous read path is affected. The synchronous SMB2_read() caller passes rdata == NULL and the memory
registration block is guarded on rdata. The memory registration failure path was pointed out by the
Sashiko AI reviewer while it was reviewing an unrelated patch to smb2_async_readv(). (CVE-2026-90125)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.700.7 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 468654

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.63

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-90125

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/17/2026

Reference Information

CVE: CVE-2026-90125