Google: sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.104.113

medium Tenable Self-Hosted Container Security Plugin ID 471765

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate
ACCESS/MODIFY events on child for special files inotify/fanotify do not allow users with no read access to
a file to subscribe to events (e.g. IN_ACCESS/IN_MODIFY), but they do allow the same user to subscribe for
watching events on children when the user has access to the parent directory (e.g. /dev). Users with no
read access to a file but with read access to its parent directory can still stat the file and see if it
was accessed/modified via atime/mtime change. The same is not true for special files (e.g. /dev/null).
Users will not generally observe atime/mtime changes when other users read/write to special files, only
when someone sets atime/mtime via utimensat(). Align fsnotify events with this stat behavior and do not
generate ACCESS/MODIFY events to parent watchers on read/write of special files. The events are still
generated to parent watchers on utimensat(). This closes some side-channels that could be possibly used
for information exfiltration [1]. [1] https://snee.la/pdf/pubs/file-notification-attacks.pdf
(CVE-2025-68788)

Solution

Update the sys-kernel/csql-kernel-6_12 library and its related packages to version 19216.104.113 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 471765

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 95.89

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2025-68788

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/13/2026

Reference Information

CVE: CVE-2025-68788