Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.395.73

high Tenable Self-Hosted Container Security Plugin ID 468843

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and receive
message requests The driver would just fetch events and receive messages until the BMC said it was done.
To avoid issues with BMCs that never say they are done, add a limit of 10 fetches at a time. In addition,
an si interface has an attn state it can return from the hardware which is supposed to cause a flag fetch
to see if the driver needs to fetch events or message or a few other things. If the attn bit gets stuck,
it's a similar problem. So allow messages in between flag fetches so the driver itself doesn't get stuck.
This is a more general fix than the previous fix for the specific bad BMC, but should fix the more general
issue of a BMC that won't stop saying it has data. This has been there from the beginning of the driver.
It's not a bug per-se, but it is accounting for bugs in BMCs. (CVE-2026-46177)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.395.73 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 468843

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-46177

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/26/2026

Reference Information

CVE: CVE-2026-46177