Echo: linux: security update to 6.1.176-1

high Tenable Cloud Security Plugin ID 461974

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: media: as102: fix to not free memory
after the device is registered in as102_usb_probe() In as102_usb driver, the following race condition
occurs: ``` CPU0 CPU1 as102_usb_probe() kzalloc(); // alloc as102_dev_t .... usb_register_dev(); fd =
sys_open("/path/to/dev"); // open as102 fd .... usb_deregister_dev(); .... kfree(); // free as102_dev_t
.... sys_close(fd); as102_release() // UAF!! as102_usb_release() kfree(); // DFB!! ``` When a USB
character device registered with usb_register_dev() is later unregistered (via usb_deregister_dev() or
disconnect), the device node is removed so new open() calls fail. However, file descriptors that are
already open do not go away immediately: they remain valid until the last reference is dropped and the
driver's .release() is invoked. In as102, as102_usb_probe() calls usb_register_dev() and then, on an error
path, does usb_deregister_dev() and frees as102_dev_t right away. If userspace raced a successful open()
before the deregistration, that open FD will later hit as102_release() --> as102_usb_release() and access
or free as102_dev_t again, occur a race to use-after-free and double-free vuln. The fix is to never
kfree(as102_dev_t) directly once usb_register_dev() has succeeded. After deregistration, defer freeing
memory to .release(). In other words, let release() perform the last kfree when the final open FD is
closed. (CVE-2026-31578)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-31578

Plugin Details

Severity: High

ID: 461974

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.84

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31578

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 4/24/2026

Reference Information

CVE: CVE-2026-31578