Echo: linux: security update to 6.1.170-1

medium Tenable Cloud Security Plugin ID 458420

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration
before IB connection is established rds_ib_get_mr() extracts the rds_ib_connection from
conn->c_transport_data and passes it to rds_ib_reg_frmr() for FRWR memory registration. On a fresh
outgoing connection, ic is allocated in rds_ib_conn_alloc() with i_cm_id = NULL because the connection
worker has not yet called rds_ib_conn_path_connect() to create the rdma_cm_id. When sendmsg() with
RDS_CMSG_RDMA_MAP is called on such a connection, the sendmsg path parses the control message before any
connection establishment, allowing rds_ib_post_reg_frmr() to dereference ic->i_cm_id->qp and crash the
kernel. The existing guard in rds_ib_reg_frmr() only checks for !ic (added in commit 9e630bcb7701), which
does not catch this case since ic is allocated early and is always non-NULL once the connection object
exists. KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP:
0010:rds_ib_post_reg_frmr+0x50e/0x920 Call Trace: rds_ib_post_reg_frmr (net/rds/ib_frmr.c:167)
rds_ib_map_frmr (net/rds/ib_frmr.c:252) rds_ib_reg_frmr (net/rds/ib_frmr.c:430) rds_ib_get_mr
(net/rds/ib_rdma.c:615) __rds_rdma_map (net/rds/rdma.c:295) rds_cmsg_rdma_map (net/rds/rdma.c:860)
rds_sendmsg (net/rds/send.c:1363) ____sys_sendmsg do_syscall_64 Add a check in rds_ib_get_mr() that
verifies ic, i_cm_id, and qp are all non-NULL before proceeding with FRMR registration, mirroring the
guard already present in rds_ib_post_inv(). Return -ENODEV when the connection is not ready, which the
existing error handling in rds_cmsg_send() converts to -EAGAIN for userspace retry and triggers
rds_conn_connect_if_down() to start the connection worker. (CVE-2026-31425)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-31425

Plugin Details

Severity: Medium

ID: 458420

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.72

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-31425

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 4/13/2026

Reference Information

CVE: CVE-2026-31425