Google: sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.104.113

medium Tenable Self-Hosted Container Security Plugin ID 472442

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: sched/deadline: only set free_cpus for
online runqueues Commit 16b269436b72 ("sched/deadline: Modify cpudl::free_cpus to reflect rd->online")
introduced the cpudl_set/clear_freecpu functions to allow the cpu_dl::free_cpus mask to be manipulated by
the deadline scheduler class rq_on/offline callbacks so the mask would also reflect this state. Commit
9659e1eeee28 ("sched/deadline: Remove cpu_active_mask from cpudl_find()") removed the check of the
cpu_active_mask to save some processing on the premise that the cpudl::free_cpus mask already reflected
the runqueue online state. Unfortunately, there are cases where it is possible for the cpudl_clear
function to set the free_cpus bit for a CPU when the deadline runqueue is offline. When this occurs while
a CPU is connected to the default root domain the flag may retain the bad state after the CPU has been
unplugged. Later, a different CPU that is transitioning through the default root domain may push a
deadline task to the powered down CPU when cpudl_find sees its free_cpus bit is set. If this happens the
task will not have the opportunity to run. One example is outlined here:
https://lore.kernel.org/lkml/[email protected] Another occurs when the last
deadline task is migrated from a CPU that has an offlined runqueue. The dequeue_task member of the
deadline scheduler class will eventually call cpudl_clear and set the free_cpus bit for the CPU. This
commit modifies the cpudl_clear function to be aware of the online state of the deadline runqueue so that
the free_cpus mask can be updated appropriately. It is no longer necessary to manage the mask outside of
the cpudl_set/clear functions so the cpudl_set/clear_freecpu functions are removed. In addition, since the
free_cpus mask is now only updated under the cpudl lock the code was changed to use the non-atomic
__cpumask functions. (CVE-2025-68780)

Solution

Update the sys-kernel/csql-kernel-6_12 library and its related packages to version 19216.104.113 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472442

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.59

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-68780

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/13/2026

Reference Information

CVE: CVE-2025-68780