Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.505.8

critical Tenable Cloud Security Plugin ID 472736

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv
length checks gss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with offset = (u8 *)(p) - (u8
*)head->iov_base; if (offset + opaque_len > rcv_buf->len) goto unwrap_failed; maj_stat =
gss_unwrap(ctx->gc_gss_ctx, offset, offset + opaque_len, rcv_buf); Both operands are u32 and the sum is
computed in u32. A reply with opaque_len near 0xffffffff makes offset + opaque_len wrap to a small value
that is below rcv_buf->len, so the bound check passes and gss_unwrap() is called with end < begin. The
check also lacks a lower bound, so any opaque_len in [0, GSS_KRB5_TOK_HDR_LEN) is accepted and forwarded
to gss_krb5_unwrap_v2(), whose pre-decrypt header reads at ptr+4 and ptr+6 then run past the token. A
krb5p NFS server returning a crafted RPCSEC_GSS reply can drive the client into out-of-bounds reads in
gss_krb5_unwrap_v2() and the rotate_left() loop that follows. Fix by replacing the single combined check
with three guards that are safe in u32 arithmetic and that enforce the RFC 4121 minimum outer token
length: if (offset > rcv_buf->len) goto unwrap_failed; if (opaque_len > rcv_buf->len - offset) goto
unwrap_failed; if (opaque_len < GSS_KRB5_TOK_HDR_LEN) goto unwrap_failed; The first guard makes the
subtraction in the second guard unconditionally safe; offset is derived from a successful
xdr_inline_decode() in the head kvec, so in practice it already satisfies the bound. The floor mirrors the
server-side check added in commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token minimum length").
(CVE-2026-89541)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.505.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 472736

Version: Revision 1.1

Type: Local

Published: 10/5/2026

Updated: 10/5/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.27

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-89541

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/11/2026

Reference Information

CVE: CVE-2026-89541