Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 20085.0.0

medium Tenable Self-Hosted Container Security Plugin ID 470985

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix race between
registration and connection abortion This fixes this race: - thread a: io_uring_enter -> register sqe ->
fuse_uring_create_ring_ent -> allocate ent but doesn't grab queue_ref yet - thread b: fuse_conn_destroy()
-> fuse_chan_abort() -> fuse_uring_abort() is a no-op due to queue ref being 0 - thread a: grabs the
queue_ref, queue_ref is now 1, rest of fuse_uring_do_register() logic executes - thread b:
fuse_chan_abort() returns, fuse_chan_wait_aborted() now runs and calls "wait_event(ring->stop_waitq,
atomic_read(&ring->queue_refs) == 0);" The abort/unmount thread will hang indefinitely in unkillable state
as nothing will decrement queue_refs or wake stop_waitq, and the ring, queue, and ent are leaked. Fix this
by checking fch->connected under fch->lock after the created ent has grabbed a ref count on the queue.
This ensures that in the scenario above, it is guaranteed that we either release the queue ref and wake up
stop_waitq (in case fuse_chan_wait_aborted() is already waiting) in fuse_uring_do_register() when we
detect !fch->connected, or if the connection is aborted after the check, it is guaranteed that the async
teardown worker will be running in the background cleaning up ents and decrementing the ent's ref on the
queue, which will unblock the eventual queue and ring teardown. (CVE-2026-68095)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 20085.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-138.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 470985

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.36

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-68095

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/10/2026

Reference Information

CVE: CVE-2026-68095