Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.299.82

high Tenable Self-Hosted Container Security Plugin ID 469771

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm: shrinker: fix shrinker_info
teardown race with expansion expand_shrinker_info() iterates all visible memcgs under shrinker_mutex,
including memcgs that have not finished ->css_online() yet. Once pn->shrinker_info has been published,
teardown must stay serialized with expand_shrinker_info() until that memcg is either fully online or no
longer visible to iteration. Today alloc_shrinker_info() breaks that rule by dropping shrinker_mutex
before freeing a partially initialized shrinker_info array, which may cause the following race: CPU0 CPU1
==== ==== css_create --> list_add_tail_rcu(&css->sibling, &parent_css->children); online_css -->
mem_cgroup_css_online --> alloc_shrinker_info --> alloc node0 info
rcu_assign_pointer(C->node0->shrinker_info, old0) alloc node1 info -> FAIL -> goto err
mutex_unlock(shrinker_mutex) shrinker_alloc() --> shrinker_memcg_alloc --> mutex_lock(shrinker_mutex)
expand_shrinker_info --> mem_cgroup_iter see the memcg expand_one_shrinker_info --> old0 =
C->node0->shrinker_info memcpy(new->unit, old0->unit, ...); free_shrinker_info --> kvfree(old0); /* double
free !! */ kvfree_rcu(old0, rcu); The same problem exists later in mem_cgroup_css_online(). If
alloc_shrinker_info() succeeds but a subsequent objcg allocation fails, the free_objcg ->
free_shrinker_info() unwind path tears down the already published pn->shrinker_info arrays without
shrinker_mutex. The expand_one_shrinker_info() can race with that teardown in the same way, leading to
use-after-free or double-free of the old shrinker_info. Fix this by serializing shrinker_info teardown
with shrinker_mutex, and by keeping alloc_shrinker_info() error cleanup inside the locked section.
(CVE-2026-64418)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.299.82 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469771

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.22

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64418

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/23/2026

Reference Information

CVE: CVE-2026-64418