Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.439.108

medium Tenable Self-Hosted Container Security Plugin ID 471862

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ext4: refresh inline data size before
write operations The cached ei->i_inline_size can become stale between the initial size check and when
ext4_update_inline_data()/ext4_create_inline_data() use it. Although ext4_get_max_inline_size() reads the
correct value at the time of the check, concurrent xattr operations can modify i_inline_size before
ext4_write_lock_xattr() is acquired. This causes ext4_update_inline_data() and ext4_create_inline_data()
to work with stale capacity values, leading to a BUG_ON() crash in ext4_write_inline_data(): kernel BUG at
fs/ext4/inline.c:1331! BUG_ON(pos + len > EXT4_I(inode)->i_inline_size); The race window: 1.
ext4_get_max_inline_size() reads i_inline_size = 60 (correct) 2. Size check passes for 50-byte write 3.
[Another thread adds xattr, i_inline_size changes to 40] 4. ext4_write_lock_xattr() acquires lock 5.
ext4_update_inline_data() uses stale i_inline_size = 60 6. Attempts to write 50 bytes but only 40 bytes
actually available 7. BUG_ON() triggers Fix this by recalculating i_inline_size via
ext4_find_inline_data_nolock() immediately after acquiring xattr_sem. This ensures
ext4_update_inline_data() and ext4_create_inline_data() work with current values that are protected from
concurrent modifications. This is similar to commit a54c4613dac1 ("ext4: fix race writing to an
inline_data file while its xattrs are changing") which fixed i_inline_off staleness. This patch addresses
the related i_inline_size staleness issue. (CVE-2025-68264)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.439.108 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 471862

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 97.01

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:C/A:C

CVSS Score Source: CVE-2025-68264

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Temporal Score: 5.5

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/16/2025

Reference Information

CVE: CVE-2025-68264