Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19216.532.121

medium Tenable Self-Hosted Container Security Plugin ID 468847

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Use sender devcom for MPV
master-up After PCIe DPC recovery, mlx5 reloads the affected functions and replays multiport affiliation
events. In the reported failure, the first relevant device error was: pcieport 0000:10:01.1: DPC:
containment event pcieport 0000:10:01.1: PCIe Bus Error: severity=Uncorrected (Fatal) pcieport
0000:10:01.1: [ 5] SDES (First) mlx5 recovered the PCI functions and resumed 0000:11:00.1. During that
resume, RDMA multiport binding replayed MLX5_DRIVER_EVENT_AFFILIATION_DONE and mlx5e sent
MPV_DEVCOM_MASTER_UP. The host then panicked with: BUG: kernel NULL pointer dereference, address:
0000000000000010 RIP: mlx5_devcom_comp_set_ready+0x5/0x40 [mlx5_core] RDI: 0000000000000000 Call trace
included: mlx5_devcom_comp_set_ready mlx5e_devcom_event_mpv mlx5_devcom_send_event mlx5_ib_bind_slave_port
mlx5r_mp_probe mlx5_pci_resume MPV devcom registration publishes mlx5e private data to the component peer
list before mlx5e_devcom_init_mpv() stores the returned component device in priv->devcom. A concurrent
master-up event can therefore reach a peer whose private data is visible but whose priv->devcom
backpointer is still NULL. MPV_DEVCOM_MASTER_UP already carries the sender/master mlx5e private data as
event_data. The ready bit is stored on the shared devcom component, not on an individual peer. Use the
sender devcom when marking the MPV component ready. This preserves the readiness transition while avoiding
a NULL dereference of the peer devcom pointer during affiliation replay after PCI error recovery.
(CVE-2026-68139)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.532.121 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 468847

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.58

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 3.7

Temporal Score: 2.7

Vector: CVSS2#AV:L/AC:H/Au:M/C:N/I:N/A:C

CVSS Score Source: CVE-2026-68139

CVSS v3

Risk Factor: Medium

Base Score: 4.1

Temporal Score: 3.6

Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/10/2026

Reference Information

CVE: CVE-2026-68139