Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.448.8

critical Tenable Self-Hosted Container Security Plugin ID 469144

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after
XDP frag adjustment veth exposes non-linear skb fragments through an xdp_buff. If an XDP program adjusts
the fragment area, veth_xdp_rcv_skb() copies xdp_frags_size back to skb->data_len but leaves skb->len
containing the old fragment contribution. After a fragment shrink, this makes skb_headlen() larger than
the actual linear area. In the reproduced UDP receive path, __skb_datagram_iter() copied 1024 bytes past
the actual linear tail to userspace, starting at struct skb_shared_info. The copied bytes included the
affected skb's nr_frags, xdp_frags_size, and a kernel pointer from skb_shinfo(skb)->frags[0]. Real packet
data was displaced by the same amount and truncated at the end. Subtract the old data_len before replacing
it and add the new data_len afterwards, keeping skb->len and skb->data_len synchronized. Additionally,
bpf_xdp_pull_data() can advance data_end while leaving frags present. The skb is then still non-linear, so
the old __skb_put(skb, off) triggers SKB_LINEAR_ASSERT(). Use skb_set_tail_pointer() and update skb->len
explicitly instead, following bpf_prog_run_generic_xdp(). Unlike __skb_put(), skb_set_tail_pointer() does
not require a linear skb. A 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by 1024
bytes from its fragment area. Before the fix, all 10 runs produced corrupted payloads. After the fix, all
10 runs matched the expected payload exactly. A forced-tailroom reproducer also exercises
bpf_xdp_pull_data() with frags still present; the old code triggers SKB_LINEAR_ASSERT(), while this fix
passes 10/10 runs. (CVE-2026-74612)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.448.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 469144

Version: Revision 1.3

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.06

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74612

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/22/2026

Reference Information

CVE: CVE-2026-74612