Echo: linux: security update to 6.1.162-1

medium Tenable Cloud Security Plugin ID 458401

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: comedi: multiq3: sanitize config
options in multiq3_attach() Syzbot identified an issue [1] in multiq3_attach() that induces a task timeout
due to open() or COMEDI_DEVCONFIG ioctl operations, specifically, in the case of multiq3 driver. This
problem arose when syzkaller managed to craft weird configuration options used to specify the number of
channels in encoder subdevice. If a particularly great number is passed to s->n_chan in multiq3_attach()
via it->options[2], then multiple calls to multiq3_encoder_reset() at the end of driver-specific attach()
method will be running for minutes, thus blocking tasks and affected devices as well. While this issue is
most likely not too dangerous for real-life devices, it still makes sense to sanitize configuration
inputs. Enable a sensible limit on the number of encoder chips (4 chips max, each with 2 channels) to stop
this behaviour from manifesting. [1] Syzbot crash: INFO: task syz.2.19:6067 blocked for more than 143
seconds. ... Call Trace: <TASK> context_switch kernel/sched/core.c:5254 [inline] __schedule+0x17c4/0x4d60
kernel/sched/core.c:6862 __schedule_loop kernel/sched/core.c:6944 [inline] schedule+0x165/0x360
kernel/sched/core.c:6959 schedule_preempt_disabled+0x13/0x30 kernel/sched/core.c:7016 __mutex_lock_common
kernel/locking/mutex.c:676 [inline] __mutex_lock+0x7e6/0x1350 kernel/locking/mutex.c:760
comedi_open+0xc0/0x590 drivers/comedi/comedi_fops.c:2868 chrdev_open+0x4cc/0x5e0 fs/char_dev.c:414
do_dentry_open+0x953/0x13f0 fs/open.c:965 vfs_open+0x3b/0x340 fs/open.c:1097 ... (CVE-2025-68258)

Solution

Update the linux library and its related packages to version 6.1.162-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68258

Plugin Details

Severity: Medium

ID: 458401

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.42

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-68258

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/17/2025

Vulnerability Publication Date: 12/16/2025

Reference Information

CVE: CVE-2025-68258