Google: sys-kernel/cchost-kernel-6_12, sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_18: security update to 19999.44.28

high Tenable Self-Hosted Container Security Plugin ID 470846

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix huge_zero_pfn race
Patch series "mm/huge_memory: fix huge_zero_pfn race", v2. There is a subtle race in the reference-counted
huge_zero_folio implementation. The fast path atomic logic fails to account for the fact that the shrinker
(which drops the final huge_zero_refcount pin) can overwrite huge_zero_pfn with the ~0UL sentinel value in
shrink_huge_zero_folio_scan() after a racing get_huge_zero_folio() installed a valid value there. This
results in huge_zero_folio being correctly set but huge_zero_pfn being set incorrectly and thus
is_huge_zero_pfn() and consequently is_huge_zero_pmd() will misidentify the huge zero folio as being an
ordinary THP folio. This can result in the huge zero folio being split and otherwise treated incorrectly.
The solution to this is very subtle as there is an atomic fast path, and thus ordering in weakly ordered
architectures has to be treated very carefully. The first commit fixes the issue by introducing a spinlock
around huge_zero_[pfn, folio, refcount] write, with careful consideration paid to load/store ordering in
the fast path. It is placed first and kept as small as possible so that it can be backported on its own.
The second commit is a pure cleanup which reworks the CONFIG_PERSISTENT_HUGE_ZERO_FOLIO logic to better
separate the persistent logic from the dynamically allocated one. This patch (of 2): If
!CONFIG_PERSISTENT_HUGE_ZERO_FOLIO, the huge_zero_folio is refcounted by huge_zero_refcount and returned
by mm_get_huge_zero_folio(). When the caller is done with the huge zero page, its reference count is
decremented. Only a shrinker can set the reference count to zero. A race can unfortunately occur between a
shrinker decrementing the reference count to zero and a concurrent page fault. This is because
shrink_huge_zero_folio_scan() might, if very unlucky, be preempted between setting huge_zero_refcount to
zero and writing an invalid value. During this time get_huge_zero_folio() could write to huge_zero_pfn
before shrink_huge_zero_folio_scan() resumes. In this event the huge zero folio will be persistently
misidentified causing the THP code path to be entered inappropriately for the huge zero folio: CPU 0 CPU 1
=======================================|================================= shrink_huge_zero_folio_scan() |
atomic_cmpxchg() sets refcount to 0 | xchg() sets huge_zero_folio to NULL | get_huge_zero_folio() | |
atomic_inc_not_zero() -> zero preempted for a long time | Allocate new huge zero folio | | Write valid
huge_zero_folio v | Write valid huge_zero_pfn Overwrite huge_zero_pfn with ~0UL <--- Invalid overwrite!
This results in is_huge_zero_pfn() and is_huge_zero_pmd() incorrectly returning false for a huge zero page
which could result in issues like the huge zero folio being incorrectly split. Note that the issue is with
huge_zero_pfn not huge_zero_folio, as get_huge_zero_folio() uses cmpxchg() gated on huge_zero_folio being
NULL with a retry loop and shrink_huge_zero_folio_scan() uses xchg() to set huge_zero_folio. Fix the issue
by introducing a spinlock, huge_zero_lock, to prevent concurrent write of huge_zero_folio, huge_zero_pfn
and huge_zero_refcount. There needs to be significant care taken here to ensure correctness: The fast path
in get_huge_zero_folio() uses atomic_inc_not_zero(), which is outside of the critical section, and means
huge zero allocation is gated on zero huge_zero_refcount. The fast path doesn't use huge_zero_lock, so the
critical section is irrelevant to it. So invariants are required - huge_zero_refcount MUST: * Only be set
in the huge_zero_lock critical section to ensure serialisation of huge_zero_pfn, huge_zero_folio and
---truncated--- (CVE-2026-74632)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19999.44.28 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-133.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 470846

Version: Revision 1.3

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.15

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74632

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/22/2026

Reference Information

CVE: CVE-2026-74632