Google: sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6: security update to 18613.75.37

medium Tenable Self-Hosted Container Security Plugin ID 472324

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: exec: don't WARN for racy path_noexec
check Both i_mode and noexec checks wrapped in WARN_ON stem from an artifact of the previous
implementation. They used to legitimately check for the condition, but that got moved up in two commits:
633fb6ac3980 ("exec: move S_ISREG() check earlier") 0fd338b2d2cd ("exec: move path_noexec() check
earlier") Instead of being removed said checks are WARN_ON'ed instead, which has some debug value.
However, the spurious path_noexec check is racy, resulting in unwarranted warnings should someone race
with setting the noexec flag. One can note there is more to perm-checking whether execve is allowed and
none of the conditions are guaranteed to still hold after they were tested for. Additionally this does not
validate whether the code path did any perm checking to begin with -- it will pass if the inode happens to
be regular. Keep the redundant path_noexec() check even though it's mindless nonsense checking for
guarantee that isn't given so drop the WARN. Reword the commentary and do small tidy ups while here.
[brauner: keep redundant path_noexec() check] (CVE-2024-50010)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18613.75.37 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472324

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-50010

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2024-50010