Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 19804.0.0

medium Tenable Self-Hosted Container Security Plugin ID 469819

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: slub: fix data loss and overflow in
krealloc() Commit 2cd8231796b5 ("mm/slub: allow to set node and align in k[v]realloc") introduced the
ability to force a reallocation if the original object does not satisfy new alignment or NUMA node, even
when the object is being shrunk. This introduced two bugs in the reallocation fallback path: 1. Data loss
during NUMA migration: The jump to 'alloc_new' happens before 'ks' and 'orig_size' are initialized. As a
result, the memcpy() in the 'alloc_new' block would copy 0 bytes into the new allocation. 2. Buffer
overflow during shrinking: When shrinking an object while forcing a new alignment, 'new_size' is smaller
than the old size. However, the memcpy() used the old size ('orig_size ?: ks'), leading to an out-of-
bounds write. The same overflow bug exists in the kvrealloc() fallback path, where the old bucket size
ksize(p) is copied into the new buffer without being bounded by the new size. A simple reproducer: // e.g.
add to lkdtm as KREALLOC_SHRINK_OVERFLOW while (1) { void *p = kmalloc(128, GFP_KERNEL); p =
krealloc_node_align(p, 64, 256, GFP_KERNEL, NUMA_NO_NODE); kfree(p); } demonstrates the issue:
================================================================== BUG: KFENCE: out-of-bounds write in
memcpy_orig+0x68/0x130 Out-of-bounds write at 0xffff8883ad757038 (120B right of kfence-#47):
memcpy_orig+0x68/0x130 krealloc_node_align_noprof+0x1c8/0x340 lkdtm_KREALLOC_SHRINK_OVERFLOW+0x8c/0xc0
[lkdtm] lkdtm_do_action+0x3a/0x60 [lkdtm] ... kfence-#47: 0xffff8883ad756fc0-0xffff8883ad756fff, size=64,
cache=kmalloc-64 allocated by task 316 on cpu 7 at 97.680481s (0.021813s ago):
krealloc_node_align_noprof+0x19c/0x340 lkdtm_KREALLOC_SHRINK_OVERFLOW+0x8c/0xc0 [lkdtm]
lkdtm_do_action+0x3a/0x60 [lkdtm] ... ==================================================================
Fix it by moving the old size calculation to the top of __do_krealloc() and bounding all copy lengths by
the new allocation size. (CVE-2026-45990)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 19804.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469819

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.76

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-45990

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/26/2026

Reference Information

CVE: CVE-2026-45990