Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12: security update to 19506.120.64

high Tenable Self-Hosted Container Security Plugin ID 472515

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic
on IPV6_CSUM GSO fallback NETIF_F_IPV6_CSUM only advertises support for checksum offload of packets
without IPv6 extension headers. Packets with extension headers must fall back onto software checksumming.
Since TSO depends on checksum offload, those must revert to GSO. The below commit introduces that
fallback. It always checks network header length. For tunneled packets, the inner header length must be
checked instead. Extend the check accordingly. A special case is tunneled packets without inner IP
protocol. Such as RFC 6951 SCTP in UDP. Those are not standard IPv6 followed by transport header either,
so also must revert to the software GSO path. (CVE-2026-43057)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.120.64 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472515

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.76

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-43057

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/23/2026

Reference Information

CVE: CVE-2026-43057