Echo: linux: security update to 6.1.170-1

medium Tenable Cloud Security Plugin ID 458707

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in
fallback from inline due to -ENOSPC If we fail to create an inline extent due to -ENOSPC, we will attempt
to go through the normal COW path, reserve an extent, create an ordered extent, etc. However we were
always freeing the reserved qgroup data, which is wrong since we will use data. Fix this by freeing the
reserved qgroup data in __cow_file_range_inline() only if we are not doing the fallback (ret is <= 0).
(CVE-2025-71269)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-71269

Plugin Details

Severity: Medium

ID: 458707

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-71269

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 3/18/2026

Reference Information

CVE: CVE-2025-71269