Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.395.4

medium Tenable Self-Hosted Container Security Plugin ID 472656

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: unshare: fix unshare_fs() handling
There's an unpleasant corner case in unshare(2), when we have a CLONE_NEWNS in flags and current->fs
hadn't been shared at all; in that case copy_mnt_ns() gets passed current->fs instead of a private copy,
which causes interesting warts in proof of correctness] > I guess if private means fs->users == 1, the
condition could still be true. Unfortunately, it's worse than just a convoluted proof of correctness.
Consider the case when we have CLONE_NEWCGROUP in addition to CLONE_NEWNS (and current->fs->users == 1).
We pass current->fs to copy_mnt_ns(), all right. Suppose it succeeds and flips current->fs->{pwd,root} to
corresponding locations in the new namespace. Now we proceed to copy_cgroup_ns(), which fails (e.g. with
-ENOMEM). We call put_mnt_ns() on the namespace created by copy_mnt_ns(), it's destroyed and its mount
tree is dissolved, but... current->fs->root and current->fs->pwd are both left pointing to now detached
mounts. They are pinning those, so it's not a UAF, but it leaves the calling process with unshare(2)
failing with -ENOMEM _and_ leaving it with pwd and root on detached isolated mounts. The last part is
clearly a bug. There is other fun related to that mess (races with pivot_root(), including the one between
pivot_root() and fork(), of all things), but this one is easy to isolate and fix - treat CLONE_NEWNS as
"allocate a new fs_struct even if it hadn't been shared in the first place". Sure, we could go for
something like "if both CLONE_NEWNS *and* one of the things that might end up failing after copy_mnt_ns()
call in create_new_namespaces() are set, force allocation of new fs_struct", but let's keep it simple -
the cost of copy_fs_struct() is trivial. Another benefit is that copy_mnt_ns() with CLONE_NEWNS *always*
gets a freshly allocated fs_struct, yet to be attached to anything. That seriously simplifies the
analysis... FWIW, that bug had been there since the introduction of unshare(2) ;-/ (CVE-2026-43472)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.395.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472656

Version: Revision 1.1

Type: Local

Published: 10/5/2026

Updated: 10/5/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.14

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-43472

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/23/2026

Reference Information

CVE: CVE-2026-43472