Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.700.7

high Tenable Self-Hosted Container Security Plugin ID 468665

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject out-of-range evcn in
mi_enum_attr() In mi_enum_attr(), the start/end VCN validation for non-resident attributes is: if (svcn >
evcn + 1) goto out; When evcn is U64_MAX the "evcn + 1" expression wraps to 0 and any svcn passes the
check. For evcn values close to U64_MAX (but not equal to it) the right-hand side is still a meaningless
near-wrap upper bound, so a malformed on-disk attribute with svcn == 0 and evcn near U64_MAX can pass
mi_enum_attr() unrejected. VCN (virtual cluster number) is a cluster index, so any valid evcn is bounded
by the volume's total cluster count, which ntfs3 holds in sbi->used.bitmap.nbits (set up in
ntfs_init_from_boot() before any caller of mi_enum_attr() runs). Reject evcn values that fall outside this
range. However, an empty non-resident attribute (no allocated clusters) is legitimately encoded with svcn
== 0 and evcn == -1 (U64_MAX), e.g. via attr->nres.evcn = cpu_to_le64((u64)vcn - 1) with vcn == 0. That
sentinel must keep passing, so exclude evcn == U64_MAX from the range check. The existing "svcn > evcn +
1" test still tolerates the sentinel ("0 > 0" is false) and continues to require svcn == 0 for it, while
the range check rejects every other out-of-range evcn and thereby also defuses the "evcn + 1" wraparound.
svcn does not need its own bound: once evcn < nbits, "svcn > evcn + 1" implies svcn <= nbits.
[[email protected]: fixed evcn check] (CVE-2026-90199)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.700.7 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 468665

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.56

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-90199

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/17/2026

Reference Information

CVE: CVE-2026-90199