Echo: linux: security update to 6.1.162-1

critical Tenable Cloud Security Plugin ID 460179

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in
ipc_msg_send_request ipc_msg_send_request() waits for a generic netlink reply using an ipc_msg_table_entry
on the stack. The generic netlink handler (handle_generic_event()/handle_response()) fills entry->response
under ipc_msg_table_lock, but ipc_msg_send_request() used to validate and free entry->response without
holding the same lock. Under high concurrency this allows a race where handle_response() is copying data
into entry->response while ipc_msg_send_request() has just freed it, leading to a slab-use-after-free
reported by KASAN in handle_generic_event(): BUG: KASAN: slab-use-after-free in
handle_generic_event+0x3c4/0x5f0 [ksmbd] Write of size 12 at addr ffff888198ee6e20 by task pool/109349 ...
Freed by task: kvfree ipc_msg_send_request [ksmbd] ksmbd_rpc_open -> ksmbd_session_rpc_open [ksmbd] Fix
by: - Taking ipc_msg_table_lock in ipc_msg_send_request() while validating entry->response, freeing it
when invalid, and removing the entry from ipc_msg_table. - Returning the final entry->response pointer to
the caller only after the hash entry is removed under the lock. - Returning NULL in the error path,
preserving the original API semantics. This makes all accesses to entry->response consistent with
handle_response(), which already updates and fills the response buffer under ipc_msg_table_lock, and
closes the race that allowed the UAF. (CVE-2025-68263)

Solution

Update the linux library and its related packages to version 6.1.162-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68263

Plugin Details

Severity: Critical

ID: 460179

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.43

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68263

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/17/2025

Vulnerability Publication Date: 12/16/2025

Reference Information

CVE: CVE-2025-68263