Echo: linux: security update to 6.1.153-1

medium Tenable Cloud Security Plugin ID 461504

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device
endpoint command timeouts This commit addresses a rarely observed endpoint command timeout which causes
kernel panic due to warn when 'panic_on_warn' is enabled and unnecessary call trace prints when
'panic_on_warn' is disabled. It is seen during fast software-controlled connect/disconnect testcases. The
following is one such endpoint command timeout that we observed: 1. Connect =======
->dwc3_thread_interrupt ->dwc3_ep0_interrupt ->configfs_composite_setup ->composite_setup ->usb_ep_queue
->dwc3_gadget_ep0_queue ->__dwc3_gadget_ep0_queue ->__dwc3_ep0_do_control_data ->dwc3_send_gadget_ep_cmd
2. Disconnect ========== ->dwc3_thread_interrupt ->dwc3_gadget_disconnect_interrupt ->dwc3_ep0_reset_state
->dwc3_ep0_end_control_data ->dwc3_send_gadget_ep_cmd In the issue scenario, in Exynos platforms, we
observed that control transfers for the previous connect have not yet been completed and end transfer
command sent as a part of the disconnect sequence and processing of USB_ENDPOINT_HALT feature request from
the host timeout. This maybe an expected scenario since the controller is processing EP commands sent as a
part of the previous connect. It maybe better to remove WARN_ON in all places where device endpoint
commands are sent to avoid unnecessary kernel panic due to warn. (CVE-2025-39801)

Solution

Update the linux library and its related packages to version 6.1.153-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-39801

Plugin Details

Severity: Medium

ID: 461504

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.42

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-39801

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 9/15/2025

Reference Information

CVE: CVE-2025-39801