Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.505.8

medium Tenable Self-Hosted Container Security Plugin ID 469431

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: SUNRPC: check rpc_sockaddr2uaddr()
return value in rpcb_register_inet4/6 rpcb_register_inet4() and rpcb_register_inet6() store the result of
rpc_sockaddr2uaddr() into map->r_addr without checking it for NULL. rpc_sockaddr2uaddr() returns NULL when
its final kstrdup() fails, and the unchecked NULL is then carried into the synchronous RPCBPROC_SET encode
path: rpcb_register_call() -> rpc_call_sync() -> rpcb_enc_getaddr() -> encode_rpcb_string(), whose first
statement is strlen(string), dereferencing NULL and oopsing the kernel. The crash reproduces under
failslab on v6.12; with KASAN the NULL dereference surfaces as a fault on the shadow of address zero:
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 [#1] PREEMPT SMP
KASAN RIP: 0010:strlen (lib/string.c:409) Call Trace: encode_rpcb_string (net/sunrpc/rpcb_clnt.c:890)
rpcb_enc_getaddr (net/sunrpc/rpcb_clnt.c:910) rpcauth_wrap_req_encode (net/sunrpc/auth.c:745) call_encode
(net/sunrpc/clnt.c:1966) __rpc_execute (net/sunrpc/sched.c:952) rpc_run_task (net/sunrpc/clnt.c:1243)
rpc_call_sync (net/sunrpc/clnt.c:1272) rpcb_v4_register (net/sunrpc/rpcb_clnt.c:500)
svc_generic_rpcbind_set nfsd_rpcbind_set svc_register svc_setup_socket svc_addsock write_ports
nfsctl_transaction_write vfs_write The crash is reachable when an in-kernel RPC service (nfsd, lockd, nfs-
callback) registers with the local rpcbind under enough memory pressure for the small GFP_KERNEL kstrdup()
in rpc_sockaddr2uaddr() to fail. The asynchronous getport path already handles this exact failure mode by
returning -ENOMEM; only the two register helpers omit the check. Mirror that handling: bail out with
-ENOMEM when rpc_sockaddr2uaddr() returns NULL, before the address is fed into the encoder.
(CVE-2026-89784)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.505.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469431

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.57

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-89784

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-89784