Echo: linux: security update to 6.12.85-1

high Tenable Cloud Security Plugin ID 459738

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confusion
with non-Ethernet ports Similar to commit 950803f72547 ("bonding: fix type confusion in
bond_setup_by_slave()") team has the same class of header_ops type confusion. For non-Ethernet ports,
team_setup_by_port() copies port_dev->header_ops directly. When the team device later calls
dev_hard_header() or dev_parse_header(), these callbacks can run with the team net_device instead of the
real lower device, so netdev_priv(dev) is interpreted as the wrong private type and can crash. The syzbot
report shows a crash in bond_header_create(), but the root cause is in team: the topology is gre -> bond
-> team, and team calls the inherited header_ops with its own net_device instead of the lower device, so
bond_header_create() receives a team device and interprets netdev_priv() as bonding private data, causing
a type confusion crash. Fix this by introducing team header_ops wrappers for create/parse, selecting a
team port under RCU, and calling the lower device callbacks with port->dev, so each callback always sees
the correct net_device context. Also pass the selected lower device to the lower parse callback, so
recursion is bounded in stacked non-Ethernet topologies and parse callbacks always run with the correct
device context. (CVE-2026-31502)

Solution

Update the linux library and its related packages to version 6.12.85-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-31502

Plugin Details

Severity: High

ID: 459738

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.09

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31502

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 4/22/2026

Reference Information

CVE: CVE-2026-31502