Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.505.8

low Tenable Self-Hosted Container Security Plugin ID 469173

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm: memcg: stop reclaim when a limit
update is superseded kernfs serializes file operations only per open file, so separate open files can
update the same memory.high or memory.max file concurrently. Both handlers store the new limit before
synchronous reclaim, but continue to use the writer's local target in the reclaim loop. If another writer
raises or removes the limit, the first writer can continue reclaiming toward a stale target. For
memory.max, this can leave the writer looping indefinitely once reclaim retries are exhausted. The OOM
path sees sufficient margin under the current limit and returns true without killing, while the writer
still compares usage against its stale target and records another OOM event. Check the current limit at
the start of each reclaim iteration and stop if it no longer matches the writer's target. Reproducer:
Populate a cgroup with anonymous memory and disable swapping. Lower memory.max from one open file, then
restore it to "max" through another open file after the new limit becomes visible. Without the patch, the
first writer remains blocked and repeatedly increments the OOM event counter. With the patch, it returns
normally. This was not motivated by a reported production workload. We found it through automated
randomized testing for our cgroup observability work and reduced it to the reproducer above.
(CVE-2026-89752)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.505.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Low

ID: 469173

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-89752

CVSS v3

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/11/2026

Reference Information

CVE: CVE-2026-89752