Echo: linux: security update to 6.1.176-1

medium Tenable Cloud Security Plugin ID 458436

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix uninitialized heap
leak via LPGETSTATUS ioctl Just like in a previous problem in this driver, usblp_ctrl_msg() will collapse
the usb_control_msg() return value to 0/-errno, discarding the actual number of bytes transferred. Ideally
that short command should be detected and error out, but many printers are known to send "incorrect"
responses back so we can't just do that. statusbuf is kmalloc(8) at probe time and never filled before the
first LPGETSTATUS ioctl. usblp_read_status() requests 1 byte. If a malicious printer responds with zero
bytes, *statusbuf is one byte of stale kmalloc heap, sign-extended into the local int status, which the
LPGETSTATUS path then copy_to_user()s directly to the ioctl caller. Fix this all by just zapping out the
memory buffer when allocated at probe time. If a later call does a short read, the data will be identical
to what the device sent it the last time, so there is no "leak" of information happening. (CVE-2026-46167)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-46167

Plugin Details

Severity: Medium

ID: 458436

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-46167

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/28/2026

Reference Information

CVE: CVE-2026-46167