Echo: linux: security update to 6.1.133-1

medium Tenable Cloud Security Plugin ID 462617

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: gpio: aggregator: protect driver attr
handlers against module unload Both new_device_store and delete_device_store touch module global resources
(e.g. gpio_aggregator_lock). To prevent race conditions with module unload, a reference needs to be held.
Add try_module_get() in these handlers. For new_device_store, this eliminates what appears to be the most
dangerous scenario: if an id is allocated from gpio_aggregator_idr but platform_device_register has not
yet been called or completed, a concurrent module unload could fail to unregister/delete the device,
leaving behind a dangling platform device/GPIO forwarder. This can result in various issues. The following
simple reproducer demonstrates these problems: #!/bin/bash while :; do # note: whether 'gpiochip0 0'
exists or not does not matter. echo 'gpiochip0 0' > /sys/bus/platform/drivers/gpio-aggregator/new_device
done & while :; do modprobe gpio-aggregator modprobe -r gpio-aggregator done & wait Starting with the
following warning, several kinds of warnings will appear and the system may become unstable: ------------[
cut here ]------------ list_del corruption, ffff888103e2e980->next is LIST_POISON1 (dead000000000100)
WARNING: CPU: 1 PID: 1327 at lib/list_debug.c:56 __list_del_entry_valid_or_report+0xa3/0x120 [...] RIP:
0010:__list_del_entry_valid_or_report+0xa3/0x120 [...] Call Trace: <TASK> ?
__list_del_entry_valid_or_report+0xa3/0x120 ? __warn.cold+0x93/0xf2 ?
__list_del_entry_valid_or_report+0xa3/0x120 ? report_bug+0xe6/0x170 ? __irq_work_queue_local+0x39/0xe0 ?
handle_bug+0x58/0x90 ? exc_invalid_op+0x13/0x60 ? asm_exc_invalid_op+0x16/0x20 ?
__list_del_entry_valid_or_report+0xa3/0x120 gpiod_remove_lookup_table+0x22/0x60
new_device_store+0x315/0x350 [gpio_aggregator] kernfs_fop_write_iter+0x137/0x1f0 vfs_write+0x262/0x430
ksys_write+0x60/0xd0 do_syscall_64+0x6c/0x180 entry_SYSCALL_64_after_hwframe+0x76/0x7e [...] </TASK> ---[
end trace 0000000000000000 ]--- (CVE-2025-21943)

Solution

Update the linux library and its related packages to version 6.1.133-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-21943

Plugin Details

Severity: Medium

ID: 462617

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-21943

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 3/20/2025

Reference Information

CVE: CVE-2025-21943