Google: sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.104.3

high Tenable Self-Hosted Container Security Plugin ID 472924

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: Fix integer overflow in
run_unpack() The MFT record relative to the file being opened contains its runlist, an array containing
information about the file's location on the physical disk. Analysis of all Call Stack paths showed that
the values of the runlist array, from which LCNs are calculated, are not validated before run_unpack
function. The run_unpack function decodes the compressed runlist data format from MFT attributes (for
example, $DATA), converting them into a runs_tree structure, which describes the mapping of virtual
clusters (VCN) to logical clusters (LCN). The NTFS3 subsystem also has a shortcut for deleting files from
MFT records - in this case, the RUN_DEALLOCATE command is sent to the run_unpack input, and the function
logic provides that all data transferred to the runlist about file or directory is deleted without
creating a runs_tree structure. Substituting the runlist in the $DATA attribute of the MFT record for an
arbitrary file can lead either to access to arbitrary data on the disk bypassing access checks to them
(since the inode access check occurs above) or to destruction of arbitrary data on the disk. Add overflow
check for addition operation. Found by Linux Verification Center (linuxtesting.org) with SVACE.
(CVE-2025-40068)

Solution

Update the sys-kernel/csql-kernel-6_12 library and its related packages to version 19216.104.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 472924

Version: Revision 1.1

Type: Local

Published: 10/6/2026

Updated: 10/6/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40068

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/23/2025

Reference Information

CVE: CVE-2025-40068