Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.439.65

high Tenable Self-Hosted Container Security Plugin ID 471724

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: fix use-after-free race
in fault handler When a page fault occurs in a secret memory file created with `memfd_secret(2)`, the
kernel will allocate a new folio for it, mark the underlying page as not-present in the direct map, and
add it to the file mapping. If two tasks cause a fault in the same page concurrently, both could end up
allocating a folio and removing the page from the direct map, but only one would succeed in adding the
folio to the file mapping. The task that failed undoes the effects of its attempt by (a) freeing the folio
again and (b) putting the page back into the direct map. However, by doing these two operations in this
order, the page becomes available to the allocator again before it is placed back in the direct mapping.
If another task attempts to allocate the page between (a) and (b), and the kernel tries to access it via
the direct map, it would result in a supervisor not-present page fault. Fix the ordering to restore the
direct map before the folio is freed. (CVE-2025-40272)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.439.65 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 471724

Version: Revision 1.2

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.47

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40272

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/6/2025

Reference Information

CVE: CVE-2025-40272