Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.624.2

high Tenable Self-Hosted Container Security Plugin ID 472616

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: check the data direction of
a C2HData PDU nvme_tcp_handle_c2h_data() finds the request by command id and checks that it has a payload,
but it does not check that the command asked for data to be read. A controller that answers a write
command with C2HData therefore reaches nvme_tcp_recv_data(), where _copy_to_iter() hits
WARN_ON_ONCE(i->data_source) and returns 0. The receive path turns that into -EFAULT and resets the
controller. No data is copied, so this is not memory corruption. What a controller gets is a kernel
warning it can raise at will, which is fatal on a host booted with panic_on_warn. The send path already
knows the direction - it consults rq_data_dir() when it builds a command - and nvme_tcp_handle_r2t()
checks the length and the offset of the request it names. The C2HData path does not check the direction at
all. Reject a C2HData PDU whose command is not a read. Rejecting it fails the command and resets the
controller, as the neighbouring check in this function does; what goes away is the warning. [ 6.885580]
------------[ cut here ]------------ [ 6.886457] WARNING: lib/iov_iter.c:193 at
_copy_to_iter+0x289/0x1330, CPU#0: kworker/0:1H/71 [ 6.888137] CPU: 0 UID: 0 PID: 71 Comm: kworker/0:1H
Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy) [ 6.891165] Workqueue: nvme_tcp_wq
nvme_tcp_io_work [ 6.891875] RIP: 0010:_copy_to_iter+0x289/0x1330 [ 6.903739] Call Trace: [ 6.904085]
<TASK> [ 6.909254] __skb_datagram_iter+0x433/0x820 [ 6.911026] skb_copy_datagram_iter+0x37/0x120 [
6.911622] nvme_tcp_recv_skb+0xa07/0x4320 [ 6.913378] __tcp_read_sock+0x1ab/0x810 [ 6.915788]
nvme_tcp_try_recv+0x152/0x1e0 [ 6.918222] nvme_tcp_io_work+0x1e4/0x6c0 [ 6.926906] </TASK> [ 6.927226]
---[ end trace 0000000000000000 ]--- [ 6.927878] nvme nvme0: queue 1 failed to copy request 0x71 data [
6.928709] nvme nvme0: receive failed: -14 (CVE-2026-89973)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.624.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472616

Version: Revision 1.1

Type: Local

Published: 10/5/2026

Updated: 10/5/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.2

Percentile: 96.35

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:C

CVSS Score Source: CVE-2026-89973

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-89973