Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 20085.0.0

critical Tenable Self-Hosted Container Security Plugin ID 470673

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file
reference at submit handshake_nl_accept_doit() needs the file pointer backing req->hr_sk->sk_socket to
survive the window between handshake_req_next() and the subsequent FD_PREPARE() and get_file(). The
submit-side sock_hold() does not provide that. sk_refcnt keeps struct sock alive, but struct socket is
owned by sock->file: when the consumer fputs the last file reference, sock_release() tears the socket down
regardless of any sock_hold. Add an hr_file pointer to struct handshake_req and acquire an explicit
reference on sock->file during handshake_req_submit(). handshake_complete() and handshake_req_cancel()
release the reference on the completion-bit-winning path. The submit error path must also release the file
reference, but after rhashtable insertion a concurrent handshake_req_cancel() can discover the request and
race the error path. Gate the error-path cleanup -- sk_destruct restoration, fput, and request destruction
-- with test_and_set_bit(HANDSHAKE_F_REQ_COMPLETED), the same serialization handshake_complete() and
handshake_req_cancel() already use. When cancel has already claimed ownership, the submit error path
returns without touching the request; socket teardown handles final destruction. The accept-side
dereferences are not yet retargeted; that change comes in the next patch. (CVE-2026-64523)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 20085.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-138.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 470673

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.13

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64523

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/25/2026

Reference Information

CVE: CVE-2026-64523