Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12: security update to 19506.120.52

high Tenable Self-Hosted Container Security Plugin ID 469011

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-
bounds access in packet corruption In netem_enqueue(), the packet corruption logic uses
get_random_u32_below(skb_headlen(skb)) to select an index for modifying skb->data. When an AF_PACKET
TX_RING sends fully non-linear packets over an IPIP tunnel, skb_headlen(skb) evaluates to 0. Passing 0 to
get_random_u32_below() takes the variable-ceil slow path which returns an unconstrained 32-bit random
integer. Using this unconstrained value as an offset into skb->data results in an out-of-bounds memory
access. Fix this by verifying skb_headlen(skb) is non-zero before attempting to corrupt the linear data
area. Fully non-linear packets will silently bypass the corruption logic. (CVE-2026-31675)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.120.52 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469011

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.49

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31675

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/25/2026

Reference Information

CVE: CVE-2026-31675