Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.624.2

medium Tenable Self-Hosted Container Security Plugin ID 472604

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm/migrate: report RCU-tasks quiescent
states in migrate_pages_batch() migrate_pages_batch() unmaps each folio before moving it, and every unmap
runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in
kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large
batch keeps the CPU busy for a long time. The loop already calls cond_resched(), but on PREEMPTION kernels
that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state. A long batch therefore
never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout,
stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet: INFO: rcu_tasks detected
stalls on tasks: 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0
state:R running task Call Trace: tdp_mmu_zap_leafs tdp_mmu_next_root gfn_to_pfn_cache_invalidate_start
kvm_mmu_notifier_invalidate_range_start __mmu_notifier_invalidate_range_start try_to_migrate_one
try_to_migrate migrate_pages_batch migrate_pages compact_zone compact_node kcompactd kthread Use
cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing. This
has also been discussed at [1] (CVE-2026-89756)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.624.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472604

Version: Revision 1.2

Type: Local

Published: 10/5/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.61

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.1

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-89756

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/11/2026

Reference Information

CVE: CVE-2026-89756