Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.299.137

critical Tenable Self-Hosted Container Security Plugin ID 469164

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping
allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range
returned by the server starts before the current fallocate offset. The skipped hole is not zero-filled,
but fallocate still returns success. A later write to that hole may therefore fail with ENOSPC. The
function queries allocated ranges so that it can preserve existing contents and write zeroes only into
holes. However, the server may return a range that starts before the current fallocate offset. For
example, assume the fallocate request is [100, 400) and the only allocated range returned by the server is
[0, 200): Request: [100, 400) Server range: [ 0, 200) allocated Correct: [100, 200) allocated data, skip
[200, 400) hole, zero-fill Current: [100, 300) skipped [300, 400) zero-filled afterwards The current code
adds the full server range length, 200, to the current offset 100 and moves to 300. As a result, the hole
in [200, 300) is skipped without being zero-filled. Fix this by advancing only over the part of the
allocated range that overlaps the current fallocate offset. Ignore ranges that end before the current
offset and reject ranges whose end offset overflows. This also prevents a malformed range length from
causing an out-of-bounds zero-buffer read. (CVE-2026-68388)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.299.137 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 469164

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.15

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-68388

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/10/2026

Reference Information

CVE: CVE-2026-68388