Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 19999.44.21

medium Tenable Self-Hosted Container Security Plugin ID 470561

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL pointer dereference in
dpll_msg_add_pin_ref_sync() When a dpll_pin is shared across multiple dpll_device instances and those
devices are being unregistered (e.g. during driver module removal), a NULL pointer dereference can occur
in dpll_msg_add_pin_ref_sync(). This happens under the following conditions: - A pin is registered with
two or more dpll devices (dpll_A, dpll_B) - The pin has ref_sync pairs with other pins - During
unregistration of dpll_A's pins, a ref_sync partner pin is unregistered first, removing it from
dpll_A->pin_refs - But since the partner pin is still registered with dpll_B, its dpll_refs is not empty,
so dpll_pin_ref_sync_pair_del() does NOT run and the partner stays in the pin's ref_sync_pins xarray -
When the pin itself is then unregistered from dpll_A, the delete notification calls
dpll_msg_add_pin_ref_sync() which finds the partner in ref_sync_pins, passes dpll_pin_available() (partner
is still registered with dpll_B), but dpll_pin_on_dpll_priv(dpll_A, partner) returns NULL because partner
was already removed from dpll_A->pin_refs - The NULL priv pointer is passed to the driver's ref_sync_get
callback, which dereferences it BUG: kernel NULL pointer dereference, address: 0000000000000034 Oops:
Oops: 0000 [#1] SMP NOPTI RIP: 0010:zl3073x_dpll_input_pin_ref_sync_get+0x73/0x80 [zl3073x] Call Trace:
dpll_msg_add_pin_ref_sync+0xb8/0x200 dpll_cmd_pin_get_one+0x3b6/0x4b0 dpll_pin_event_send+0x72/0x140
__dpll_pin_unregister+0x5a/0x2b0 dpll_pin_unregister+0x49/0x70 Fix this by skipping ref_sync pins whose
priv pointer cannot be resolved for the current dpll device. (CVE-2026-68378)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 19999.44.21 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 470561

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.36

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-68378

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/10/2026

Reference Information

CVE: CVE-2026-68378