Google: sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.0.53

medium Tenable Self-Hosted Container Security Plugin ID 468908

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix soft lockup in
br_multicast_query_expired() When set multicast_query_interval to a large value, the local variable 'time'
in br_multicast_send_query() may overflow. If the time is smaller than jiffies, the timer will expire
immediately, and then call mod_timer() again, which creates a loop and may trigger the following soft
lockup issue. watchdog: BUG: soft lockup - CPU#1 stuck for 221s! [rb_consumer:66] CPU: 1 UID: 0 PID: 66
Comm: rb_consumer Not tainted 6.16.0+ #259 PREEMPT(none) Call Trace: <IRQ> __netdev_alloc_skb+0x2e/0x3a0
br_ip6_multicast_alloc_query+0x212/0x1b70 __br_multicast_send_query+0x376/0xac0
br_multicast_send_query+0x299/0x510 br_multicast_query_expired.constprop.0+0x16d/0x1b0
call_timer_fn+0x3b/0x2a0 __run_timers+0x619/0x950 run_timer_softirq+0x11c/0x220
handle_softirqs+0x18e/0x560 __irq_exit_rcu+0x158/0x1a0 sysvec_apic_timer_interrupt+0x76/0x90 </IRQ> This
issue can be reproduced with: ip link add br0 type bridge echo 1 >
/sys/class/net/br0/bridge/multicast_querier echo 0xffffffffffffffff >
/sys/class/net/br0/bridge/multicast_query_interval ip link set dev br0 up The
multicast_startup_query_interval can also cause this issue. Similar to the commit 99b40610956a ("net:
bridge: mcast: add and enforce query interval minimum"), add check for the query interval maximum to fix
this issue. (CVE-2025-39773)

Solution

Update the sys-kernel/csql-kernel-6_12 library and its related packages to version 19216.0.53 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 468908

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.15

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-39773

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/11/2025

Reference Information

CVE: CVE-2025-39773