Google: sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6: security update to 18613.164.4

medium Tenable Self-Hosted Container Security Plugin ID 472342

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET
for NT_ARM_TAGGED_ADDR_CTRL Currently tagged_addr_ctrl_set() doesn't initialize the temporary 'ctrl'
variable, and a SETREGSET call with a length of zero will leave this uninitialized. Consequently
tagged_addr_ctrl_set() will consume an arbitrary value, potentially leaking up to 64 bits of memory from
the kernel stack. The read is limited to a specific slot on the stack, and the issue does not provide a
write mechanism. As set_tagged_addr_ctrl() only accepts values where bits [63:4] zero and rejects other
values, a partial SETREGSET attempt will randomly succeed or fail depending on the value of the
uninitialized value, and the exposure is significantly limited. Fix this by initializing the temporary
value before copying the regset from userspace, as for other regsets (e.g. NT_PRSTATUS, NT_PRFPREG,
NT_ARM_SYSTEM_CALL). In the case of a zero-length write, the existing value of the tagged address ctrl
will be retained. The NT_ARM_TAGGED_ADDR_CTRL regset is only visible in the user_aarch64_view used by a
native AArch64 task to manipulate another native AArch64 task. As get_tagged_addr_ctrl() only returns an
error value when called for a compat task, tagged_addr_ctrl_get() and tagged_addr_ctrl_set() should never
observe an error value from get_tagged_addr_ctrl(). Add a WARN_ON_ONCE() to both to indicate that such an
error would be unexpected, and error handlnig is not missing in either case. (CVE-2024-57874)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18613.164.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472342

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.65

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:N/A:C

CVSS Score Source: CVE-2024-57874

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/8/2025

Reference Information

CVE: CVE-2024-57874