Echo: linux: security update to 6.12.69-1

high Tenable Cloud Security Plugin ID 460977

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: Input: alps - fix use-after-free bugs
caused by dev3_register_work The dev3_register_work delayed work item is initialized within
alps_reconnect() and scheduled upon receipt of the first bare PS/2 packet from an external PS/2 device
connected to the ALPS touchpad. During device detachment, the original implementation calls
flush_workqueue() in psmouse_disconnect() to ensure completion of dev3_register_work. However, the
flush_workqueue() in psmouse_disconnect() only blocks and waits for work items that were already queued to
the workqueue prior to its invocation. Any work items submitted after flush_workqueue() is called are not
included in the set of tasks that the flush operation awaits. This means that after flush_workqueue() has
finished executing, the dev3_register_work could still be scheduled. Although the psmouse state is set to
PSMOUSE_CMD_MODE in psmouse_disconnect(), the scheduling of dev3_register_work remains unaffected. The
race condition can occur as follows: CPU 0 (cleanup path) | CPU 1 (delayed work) psmouse_disconnect() |
psmouse_set_state() | flush_workqueue() | alps_report_bare_ps2_packet() alps_disconnect() |
psmouse_queue_work() kfree(priv); // FREE | alps_register_bare_ps2_mouse() | priv = container_of(work...);
// USE | priv->dev3 // USE Add disable_delayed_work_sync() in alps_disconnect() to ensure that
dev3_register_work is properly canceled and prevented from executing after the alps_data structure has
been deallocated. This bug is identified by static analysis. (CVE-2025-68822)

Solution

Update the linux library and its related packages to version 6.12.69-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68822

Plugin Details

Severity: High

ID: 460977

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68822

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2026

Vulnerability Publication Date: 1/13/2026

Reference Information

CVE: CVE-2025-68822