Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.299.3

high Tenable Self-Hosted Container Security Plugin ID 469328

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xfrm: Check for underflow in
xfrm_state_mtu Leo Lin reported OOB write issue in esp component: xfrm_state_mtu() returns u32 but
performs its arithmetic in unsigned modulo-2^32 space using an attacker-influenced "header_len + authsize
+ net_adj" subtracted from a small "mtu" argument. A nobody user can install an IPv4 ESP tunnel SA with a
large authentication key (XFRMA_ALG_AUTH_TRUNC, e.g. hmac(sha512), 64-byte key, 64-byte trunc), configure
a small interface MTU (68 bytes), and set XFRMA_TFCPAD to a large value. When a single UDP datagram is
then sent through the tunnel, xfrm_state_mtu() underflows to a near-2^32 value, and esp_output() consumes
it as a signed int via: padto = min(x->tfcpad, xfrm_state_mtu(x, mtu_cached)) esp.tfclen = padto -
skb->len (assigned to int) esp.tfclen ends up negative (e.g. -207). It is sign-extended to size_t when
passed to memset() inside esp_output_fill_trailer(), producing a ~16 EB write of zeroes at
skb_tail_pointer(skb). KASAN logs it as "Write of size 18446744073709551537 at addr ffff888...". Check for
underflow and return 1. This causes the sendmsg attempt to fail with ENETUNREACH. (CVE-2026-64009)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.299.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469328

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.13

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64009

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/22/2026

Reference Information

CVE: CVE-2026-64009