Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.164.4

medium Tenable Self-Hosted Container Security Plugin ID 472298

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: smb: During unmount, ensure all cached
dir instances drop their dentry The unmount process (cifs_kill_sb() calling close_all_cached_dirs()) can
race with various cached directory operations, which ultimately results in dentries not being dropped and
these kernel BUGs: BUG: Dentry ffff88814f37e358{i=1000000000080,n=/} still in use (2) [unmount of cifs
cifs] VFS: Busy inodes after unmount of cifs (cifs) ------------[ cut here ]------------ kernel BUG at
fs/super.c:661! This happens when a cfid is in the process of being cleaned up when, and has been removed
from the cfids->entries list, including: - Receiving a lease break from the server - Server reconnection
triggers invalidate_all_cached_dirs(), which removes all the cfids from the list - The laundromat thread
decides to expire an old cfid. To solve these problems, dropping the dentry is done in queued work done in
a newly-added cfid_put_wq workqueue, and close_all_cached_dirs() flushes that workqueue after it drops all
the dentries of which it's aware. This is a global workqueue (rather than scoped to a mount), but the
queued work is minimal. The final cleanup work for cleaning up a cfid is performed via work queued in the
serverclose_wq workqueue; this is done separate from dropping the dentries so that close_all_cached_dirs()
doesn't block on any server operations. Both of these queued works expect to invoked with a cfid reference
and a tcon reference to avoid those objects from being freed while the work is ongoing. While we're here,
add proper locking to close_all_cached_dirs(), and locking around the freeing of cfid->dentry.
(CVE-2024-53176)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.164.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472298

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-53176

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/27/2024

Reference Information

CVE: CVE-2024-53176