Echo: linux: security update to 6.1.177-1

medium Tenable Cloud Security Plugin ID 457652

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: agp/amd64: Fix broken error
propagation in agp_amd64_probe() A NULL pointer dereference was observed in the AMD64 AGP driver when
running in a virtualized environment (e.g. qemu/kvm) without a physical AMD northbridge. The crash occurs
in amd64_fetch_size() when attempting to dereference the pointer returned by node_to_amd_nb(0). The root
cause of this crash is broken error propagation in agp_amd64_probe(): When no AMD northbridges are found,
cache_nbs() correctly returns -ENODEV. However, the probe function erroneously checks the return value
against exactly -1, rather than < 0. As a result, the hardware absence error is masked, allowing the
driver to improperly proceed with initialization. It eventually calls agp_add_bridge(), which invokes
amd64_fetch_size(). Since the hardware does not exist, node_to_amd_nb(0) returns NULL, leading to a
General Protection Fault (GPF) when accessing its ->misc member. Fix the issue by correcting the error
check in agp_amd64_probe() to abort properly when cache_nbs() returns any negative error code. This
prevents the driver from erroneously proceeding without hardware, thereby avoiding the subsequent NULL
pointer dereference at its source. (CVE-2026-53325)

Solution

Update the linux library and its related packages to version 6.1.177-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-53325

Plugin Details

Severity: Medium

ID: 457652

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.96

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-53325

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/29/2026

Vulnerability Publication Date: 6/29/2026

Reference Information

CVE: CVE-2026-53325