Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.448.8

high Tenable Self-Hosted Container Security Plugin ID 468790

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: virtio_pci: fix vq info pointer lookup
via wrong index Unbinding a virtio balloon device: echo virtio0 >
/sys/bus/virtio/drivers/virtio_balloon/unbind triggers a NULL pointer dereference. The dmesg says: BUG:
kernel NULL pointer dereference, address: 0000000000000008 [...] RIP:
0010:__list_del_entry_valid_or_report+0x5/0xf0 Call Trace: <TASK> vp_del_vqs+0x121/0x230
remove_common+0x135/0x150 virtballoon_remove+0xee/0x100 virtio_dev_remove+0x3b/0x80
device_release_driver_internal+0x187/0x2c0 unbind_store+0xb9/0xe0
kernfs_fop_write_iter.llvm.11660790530567441834+0xf6/0x180 vfs_write+0x2a9/0x3b0 ksys_write+0x5c/0xd0
do_syscall_64+0x54/0x230 entry_SYSCALL_64_after_hwframe+0x29/0x31 [...] </TASK> The virtio_balloon device
registers 5 queues (inflate, deflate, stats, free_page, reporting) but only the first two are
unconditional. The stats, free_page and reporting queues are each conditional on their respective feature
bits. When any of these features are absent, the corresponding vqs_info entry has name == NULL, creating
holes in the array. The root cause is an indexing mismatch introduced when vq info storage was changed to
be passed as an argument. vp_find_vqs_msix() and vp_find_vqs_intx() store the info pointer at
vp_dev->vqs[i], where 'i' is the caller's sparse array index. However, the virtqueue itself gets vq->index
assigned from queue_idx, a dense index that skips NULL entries. When holes exist, 'i' and queue_idx
diverge. Later, vp_del_vqs() looks up info via vp_dev->vqs[vq->index] using the dense index into the
sparsely-populated array, and hits NULL. Fix this by storing info at vp_dev->vqs[queue_idx] instead of
vp_dev->vqs[i], so the store index matches the lookup index (vq->index). Apply the fix to both the MSIX
and INTX paths. (CVE-2026-64457)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.448.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 468790

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.18

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64457

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/23/2026

Reference Information

CVE: CVE-2026-64457