Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.655.6

medium Tenable Self-Hosted Container Security Plugin ID 469224

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ntfs3: cap RESTART_TABLE free-chain
walker at rt->used A crafted NTFS3 disk image triggers an in-kernel infinite loop at mount time, hanging
the mounting thread and firing the soft-lockup watchdog within ~22s on multi-CPU hosts (panic with
kernel.softlockup_panic=1). The bug is reachable from desktop USB auto-mount on distributions where
udisks2 routes the NTFS signature to the in-tree ntfs3 driver (Arch family and an increasing fraction of
Fedora / openSUSE / RHEL deployments); CAP_SYS_ADMIN-class manual mount elsewhere. check_rstbl()'s second
walker iterates the free-entry singly-linked list headed by rt->first_free with no upper bound on
iteration count: for (off = ff; off;) { if (off == RESTART_ENTRY_ALLOCATED) return false; off =
le32_to_cpu(*(__le32 *)Add2Ptr(rt, off)); if (off > ts - sizeof(__le32)) return false; } The existing
guards cover three exits: end-of-list (off == 0), the in-use marker (off == RESTART_ENTRY_ALLOCATED), and
out-of-bounds (off > ts - sizeof(__le32)). None of the three prevents an in-bounds cycle. A crafted on-
disk RESTART_TABLE whose free chain contains a self-loop or A->B->A cycle whose offsets satisfy: - in
range [sizeof(struct RESTART_TABLE), ts - sizeof(__le32)] - (off - sizeof(struct RESTART_TABLE)) % rsize
== 0 passes all existing guards and spins the mount-time thread forever. Reproduced in UML by hand-forging
a 2 MB NTFS3 image whose journal RESTART_TABLE first_free = 0x18 and whose entry at offset 0x18 stores
0x18 as its next pointer; mount of the forged image with the in-tree ntfs3 driver never returns. Bound the
walker by rt->used. Each entry on a legitimate free chain is unique, and the total slot count is ne =
le16_to_cpu (rt->used). A traversal that visits more than ne slots is by construction malformed; reject it
as a corrupt RESTART_TABLE. After this patch, mount of the forged image returns with -EINVAL and a
log_replay failure message, and mkntfs-produced legitimate images mount cleanly (verified in the same UML
harness). (CVE-2026-72193)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.655.6 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469224

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-72193

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-72193