Echo: linux: security update to 6.1.158-1

high Tenable Cloud Security Plugin ID 455149

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_acm: Refactor bind path
to use __free() After an bind/unbind cycle, the acm->notify_req is left stale. If a subsequent bind fails,
the unified error label attempts to free this stale request, leading to a NULL pointer dereference when
accessing ep->ops->free_request. Refactor the error handling in the bind path to use the __free()
automatic cleanup mechanism. Unable to handle kernel NULL pointer dereference at virtual address
0000000000000020 Call trace: usb_ep_free_request+0x2c/0xec gs_free_req+0x30/0x44 acm_bind+0x1b8/0x1f4
usb_add_function+0xcc/0x1f0 configfs_composite_bind+0x468/0x588 gadget_bind_driver+0x104/0x270
really_probe+0x190/0x374 __driver_probe_device+0xa0/0x12c driver_probe_device+0x3c/0x218
__device_attach_driver+0x14c/0x188 bus_for_each_drv+0x10c/0x168 __device_attach+0xfc/0x198
device_initial_probe+0x14/0x24 bus_probe_device+0x94/0x11c device_add+0x268/0x48c
usb_add_gadget+0x198/0x28c dwc3_gadget_init+0x700/0x858 __dwc3_set_mode+0x3cc/0x664
process_scheduled_works+0x1d8/0x488 worker_thread+0x244/0x334 kthread+0x114/0x1bc ret_from_fork+0x10/0x20
(CVE-2025-40094)

Solution

Update the linux library and its related packages to version 6.1.158-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-40094

Plugin Details

Severity: High

ID: 455149

Version: Revision 1.2

Type: Local

Published: 10/1/2026

Updated: 10/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40094

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/30/2025

Vulnerability Publication Date: 10/30/2025

Reference Information

CVE: CVE-2025-40094