Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12: security update to 19506.120.44

high Tenable Self-Hosted Container Security Plugin ID 472524

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ext4: convert inline data to extents
when truncate exceeds inline size Add a check in ext4_setattr() to convert files from inline data storage
to extent-based storage when truncate() grows the file size beyond the inline capacity. This prevents the
filesystem from entering an inconsistent state where the inline data flag is set but the file size exceeds
what can be stored inline. Without this fix, the following sequence causes a kernel BUG_ON(): 1. Mount
filesystem with inode that has inline flag set and small size 2. truncate(file, 50MB) - grows size but
inline flag remains set 3. sendfile() attempts to write data 4. ext4_write_inline_data() hits
BUG_ON(write_size > inline_capacity) The crash occurs because ext4_write_inline_data() expects inline
storage to accommodate the write, but the actual inline capacity (~60 bytes for i_block + ~96 bytes for
xattrs) is far smaller than the file size and write request. The fix checks if the new size from setattr
exceeds the inode's actual inline capacity (EXT4_I(inode)->i_inline_size) and converts the file to extent-
based storage before proceeding with the size change. This addresses the root cause by ensuring the inline
data flag and file size remain consistent during truncate operations. (CVE-2026-31452)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.120.44 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472524

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.96

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31452

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/22/2026

Reference Information

CVE: CVE-2026-31452