Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.395.4

medium Tenable Self-Hosted Container Security Plugin ID 472933

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: cgroup: fix race between task
migration and iteration When a task is migrated out of a css_set, cgroup_migrate_add_task() first moves it
from cset->tasks to cset->mg_tasks via: list_move_tail(&task->cg_list, &cset->mg_tasks); If a
css_task_iter currently has it->task_pos pointing to this task, css_set_move_task() calls
css_task_iter_skip() to keep the iterator valid. However, since the task has already been moved to
->mg_tasks, the iterator is advanced relative to the mg_tasks list instead of the original tasks list. As
a result, remaining tasks on cset->tasks, as well as tasks queued on cset->mg_tasks, can be skipped by
iteration. Fix this by calling css_set_skip_task_iters() before unlinking task->cg_list from cset->tasks.
This advances all active iterators to the next task on cset->tasks, so iteration continues correctly even
when a task is concurrently being migrated. This race is hard to hit in practice without instrumentation,
but it can be reproduced by artificially slowing down cgroup_procs_show(). For example, on an Android
device a temporary /sys/kernel/cgroup/cgroup_test knob can be added to inject a delay into
cgroup_procs_show(), and then: 1) Spawn three long-running tasks (PIDs 101, 102, 103). 2) Create a test
cgroup and move the tasks into it. 3) Enable a large delay via /sys/kernel/cgroup/cgroup_test. 4) In one
shell, read cgroup.procs from the test cgroup. 5) Within the delay window, in another shell migrate PID
102 by writing it to a different cgroup.procs file. Under this setup, cgroup.procs can intermittently show
only PID 101 while skipping PID 103. Once the migration completes, reading the file again shows all tasks
as expected. Note that this change does not allow removing the existing css_set_skip_task_iters() call in
css_set_move_task(). The new call in cgroup_migrate_add_task() only handles iterators that are racing with
migration while the task is still on cset->tasks. Iterators may also start after the task has been moved
to cset->mg_tasks. If we dropped css_set_skip_task_iters() from css_set_move_task(), such iterators could
keep task_pos pointing to a migrating task, causing css_task_iter_advance() to malfunction on the
destination css_set, up to and including crashes or infinite loops. The race window between migration and
iteration is very small, and css_task_iter is not on a hot path. In the worst case, when an iterator is
positioned on the first thread of the migrating process, cgroup_migrate_add_task() may have to skip
multiple tasks via css_set_skip_task_iters(). However, this only happens when migration and iteration
actually race, so the performance impact is negligible compared to the correctness fix provided here.
(CVE-2026-43439)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.395.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 472933

Version: Revision 1.1

Type: Local

Published: 10/6/2026

Updated: 10/6/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.63

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-43439

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/23/2026

Reference Information

CVE: CVE-2026-43439