Echo: linux: security update to 6.12.57-1

medium Tenable Cloud Security Plugin ID 461172

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: Don't block input queue by
waiting MSC Currently gsm_queue() processes incoming frames and when opening a DLC channel it calls
gsm_dlci_open() which calls gsm_modem_update(). If basic mode is used it calls gsm_modem_upd_via_msc() and
it cannot block the input queue by waiting the response to come into the same input queue. Instead allow
sending Modem Status Command without waiting for remote end to respond. Define a new function
gsm_modem_send_initial_msc() for this purpose. As MSC is only valid for basic encoding, it does not do
anything for advanced or when convergence layer type 2 is used. (CVE-2025-40071)

Solution

Update the linux library and its related packages to version 6.12.57-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-40071

Plugin Details

Severity: Medium

ID: 461172

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.25

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-40071

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/30/2025

Vulnerability Publication Date: 10/28/2025

Reference Information

CVE: CVE-2025-40071