Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.395.4

medium Tenable Self-Hosted Container Security Plugin ID 469132

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ipvs: fix NULL deref in
ip_vs_add_service error path When ip_vs_bind_scheduler() succeeds in ip_vs_add_service(), the local
variable sched is set to NULL. If ip_vs_start_estimator() subsequently fails, the out_err cleanup calls
ip_vs_unbind_scheduler(svc, sched) with sched == NULL. ip_vs_unbind_scheduler() passes the cur_sched NULL
check (because svc->scheduler was set by the successful bind) but then dereferences the NULL sched
parameter at sched->done_service, causing a kernel panic at offset 0x30 from NULL. Oops: general
protection fault, [..] [#1] PREEMPT SMP KASAN NOPTI KASAN: null-ptr-deref in range
[0x0000000000000030-0x0000000000000037] RIP: 0010:ip_vs_unbind_scheduler
(net/netfilter/ipvs/ip_vs_sched.c:69) Call Trace: <TASK> ip_vs_add_service.isra.0
(net/netfilter/ipvs/ip_vs_ctl.c:1500) do_ip_vs_set_ctl (net/netfilter/ipvs/ip_vs_ctl.c:2809) nf_setsockopt
(net/netfilter/nf_sockopt.c:102) [..] Fix by simply not clearing the local sched variable after a
successful bind. ip_vs_unbind_scheduler() already detects whether a scheduler is installed via
svc->scheduler, and keeping sched non-NULL ensures the error path passes the correct pointer to both
ip_vs_unbind_scheduler() and ip_vs_scheduler_put(). While the bug is older, the problem popups in more
recent kernels (6.2), when the new error path is taken after the ip_vs_start_estimator() call.
(CVE-2026-43086)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.395.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469132

Version: Revision 1.3

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.77

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-43086

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/6/2026

Reference Information

CVE: CVE-2026-43086