Echo: linux: security update to 6.1.170-1

medium Tenable Cloud Security Plugin ID 463030

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: can: ems_usb:
ems_usb_read_bulk_callback(): check the proper length of a message When looking at the data in a USB urb,
the actual_length is the size of the buffer passed to the driver, not the transfer_buffer_length which is
set by the driver as the max size of the buffer. When parsing the messages in ems_usb_read_bulk_callback()
properly check the size both at the beginning of parsing the message to make sure it is big enough for the
expected structure, and at the end of the message to make sure we don't overflow past the end of the
buffer for the next message. (CVE-2026-23307)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-23307

Plugin Details

Severity: Medium

ID: 463030

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.72

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-23307

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 3/25/2026

Reference Information

CVE: CVE-2026-23307