Google: sys-kernel/cchost-kernel-6_18, sys-kernel/csql-kernel-6_18, sys-kernel/lakitu-kernel-6_18, sys-kernel/lakitu-nc-kernel-6_18: security update to 20085.0.0

critical Tenable Self-Hosted Container Security Plugin ID 471546

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio()
restore index before retrying In __filemap_add_folio()'s split-a-conflict loop, xas_set_order() is applied
repeatedly: each application modifies xas.xa_index, rounding it down according to the split_order
attempted at that stage: and if all goes as intended, it eventually (or immediately) converges on an
xas_try_split() to the required folio_order, with xas.xa_index now the same as index: then xas_store()
puts the new folio into the xarray there. But if a new node was needed, and GFP_NOWAIT allocation did not
get one, the lock is dropped, xas_nomem() used to allocate, and sequence retried. If (that part of) the
xarray is unchanged when the lock is reacquired, no problem. But what if the conflict was meanwhile
resolved by another thread (perhaps even doing the same thing, inserting a folio at that same index)?
Isn't there a danger of now putting our folio into the xarray at an intermediate rounded-down index? With
!folio_contains() bug to follow, when CONFIG_DEBUG_VM=y is checking for that. Fix this with an
xas_set_order() to restore the original xas.xa_index at the bottom of the loop, so the retry does a full
re-evaluation after reacquiring the lock, and cannot reach xas_store() with the wrong index. Production
was suffering from rare SIGILLs and SIGSEGVs, executable text found a page away from where it belonged,
!folio_contains() bug hit when debug enabled: symptoms not seen since this patch went in. (CVE-2026-74591)

Solution

Update the sys-kernel/cchost-kernel-6_18 library and its related packages to version 20085.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-138.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 471546

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.19

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74591

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/22/2026

Reference Information

CVE: CVE-2026-74591