Echo: linux: security update to 6.1.187-1

medium Tenable Cloud Security Plugin ID 457139

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from
lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via
bpf_test_run() without without entering input_action_end_bpf() first. Martin KaFai Lau said that self test
for BPF_PROG_TYPE_LWT_SEG6LOCAL probably didn't work since it was introduced in commit 04d4b274e2a ("ipv6:
sr: Add seg6local action End.BPF"). The reason is that the per-CPU variable seg6_bpf_srh_states::srh is
never assigned in the self test case but each BPF function expects it. Remove test_run for
BPF_PROG_TYPE_LWT_SEG6LOCAL. (CVE-2024-46754)

Solution

Update the linux library and its related packages to version 6.1.187-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-46754

Plugin Details

Severity: Medium

ID: 457139

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-46754

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 9/18/2024

Reference Information

CVE: CVE-2024-46754