Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.439.70

medium Tenable Self-Hosted Container Security Plugin ID 472036

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: futex: Don't leak robust_list pointer
on exec race sys_get_robust_list() and compat_get_robust_list() use ptrace_may_access() to check if the
calling task is allowed to access another task's robust_list pointer. This check is racy against a
concurrent exec() in the target process. During exec(), a task may transition from a non-privileged binary
to a privileged one (e.g., setuid binary) and its credentials/memory mappings may change. If
get_robust_list() performs ptrace_may_access() before this transition, it may erroneously allow access to
sensitive information after the target becomes privileged. A racy access allows an attacker to exploit a
window during which ptrace_may_access() passes before a target process transitions to a privileged state
via exec(). For example, consider a non-privileged task T that is about to execute a setuid-root binary.
An attacker task A calls get_robust_list(T) while T is still unprivileged. Since ptrace_may_access()
checks permissions based on current credentials, it succeeds. However, if T begins exec immediately
afterwards, it becomes privileged and may change its memory mappings. Because get_robust_list() proceeds
to access T->robust_list without synchronizing with exec() it may read user-space pointers from a now-
privileged process. This violates the intended post-exec access restrictions and could expose sensitive
memory addresses or be used as a primitive in a larger exploit chain. Consequently, the race can lead to
unauthorized disclosure of information across privilege boundaries and poses a potential security risk.
Take a read lock on signal->exec_update_lock prior to invoking ptrace_may_access() and accessing the
robust_list/compat_robust_list. This ensures that the target task's exec state remains stable during the
check, allowing for consistent and synchronized validation of credentials. (CVE-2025-40341)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.439.70 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472036

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.14

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-40341

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/9/2025

Reference Information

CVE: CVE-2025-40341