Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12: security update to 19216.220.38

medium Tenable Self-Hosted Container Security Plugin ID 472448

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb_pmd_shared()
Patch series "mm/hugetlb: fixes for PMD table sharing (incl. using mmu_gather)", v3. One functional fix,
one performance regression fix, and two related comment fixes. I cleaned up my prototype I recently shared
[1] for the performance fix, deferring most of the cleanups I had in the prototype to a later point. While
doing that I identified the other things. The goal of this patch set is to be backported to stable trees
"fairly" easily. At least patch #1 and #4. Patch #1 fixes hugetlb_pmd_shared() not detecting any sharing
Patch #2 + #3 are simple comment fixes that patch #4 interacts with. Patch #4 is a fix for the reported
performance regression due to excessive IPI broadcasts during fork()+exit(). The last patch is all about
TLB flushes, IPIs and mmu_gather. Read: complicated There are plenty of cleanups in the future to be had +
one reasonable optimization on x86. But that's all out of scope for this series. Runtime tested, with a
focus on fixing the performance regression using the original reproducer [2] on x86. This patch (of 4): We
switched from (wrongly) using the page count to an independent shared count. Now, shared page tables have
a refcount of 1 (excluding speculative references) and instead use ptdesc->pt_share_count to identify
sharing. We didn't convert hugetlb_pmd_shared(), so right now, we would never detect a shared PMD table as
such, because sharing/unsharing no longer touches the refcount of a PMD table. Page migration, like
mbind() or migrate_pages() would allow for migrating folios mapped into such shared PMD tables, even
though the folios are not exclusive. In smaps we would account them as "private" although they are
"shared", and we would be wrongly setting the PM_MMAP_EXCLUSIVE in the pagemap interface. Fix it by
properly using ptdesc_pmd_is_shared() in hugetlb_pmd_shared(). (CVE-2026-23100)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.220.38 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472448

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 96.43

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-23100

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2/4/2026

Reference Information

CVE: CVE-2026-23100