Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.448.36

high Tenable Self-Hosted Container Security Plugin ID 469619

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: bound SGL data length
before allocating command buffers nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length and,
for the in-capsule offset descriptor (type 0x01), checks it against port->inline_data_size before use. Any
other SGL descriptor type -- including the non-inline transport SGL data-block descriptor (type
(NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A, the type a real host uses for out-of-
capsule writes) skips that check entirely and falls straight through to: cmd->req.sg = sgl_alloc(len,
GFP_KERNEL, &cmd->req.sg_cnt); with len taken directly from the wire, unbounded up to 4 GiB.
nvmet_req_init() only parses the command and never inspects sgl->length, and nvmet_check_transfer_len() --
the only other place transfer_len is validated -- runs later, from req->execute(), after the allocation
has already happened. For a write command the target responds with an R2T and parks the command waiting
for the host to send the data; if the host (or an unauthenticated peer that simply never follows up) never
does, the sgl_alloc() buffer stays resident for the life of the command. NVMe/TCP has no mandatory
authentication in the default configuration, so any peer able to reach the target portal and complete a
Fabrics connect can drive this with a single crafted command, repeatable across queues and connections for
amplification. This is unbounded kernel memory allocation triggered by a remote, effectively
unauthenticated peer. Validate len against the same NVMET_TCP_MAXH2CDATA ceiling this file already uses to
bound per-PDU H2C data, for every SGL descriptor type, before doing any allocation. This closes the gap
for the non-inline descriptor while leaving the existing, tighter inline_data_size check in place for the
in-capsule case. Runtime-verified on a v6.19 KASAN stand: with this bound in place, a crafted write
command carrying an oversized non-inline SGL length is rejected before sgl_alloc() runs, where the same
request previously drove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that stayed resident
pending an R2T the host never satisfies. (CVE-2026-80789)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.448.36 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469619

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.23

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-80789

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/4/2026

Reference Information

CVE: CVE-2026-80789