Google: sys-kernel/csql-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.439.45

high Tenable Self-Hosted Container Security Plugin ID 471789

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative offsets for ALU
ops When verifying BPF programs, the check_alu_op() function validates instructions with ALU operations.
The 'offset' field in these instructions is a signed 16-bit integer. The existing check 'insn->off > 1'
was intended to ensure the offset is either 0, or 1 for BPF_MOD/BPF_DIV. However, because 'insn->off' is
signed, this check incorrectly accepts all negative values (e.g., -1). This commit tightens the validation
by changing the condition to '(insn->off != 0 && insn->off != 1)'. This ensures that any value other than
the explicitly permitted 0 and 1 is rejected, hardening the verifier against malformed BPF programs.
(CVE-2025-40169)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18613.439.45 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 471789

Version: Revision 1.2

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.83

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40169

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/27/2025

Reference Information

CVE: CVE-2025-40169