Echo: linux: security update to 6.1.158-1

high Tenable Cloud Security Plugin ID 463257

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix potential double free
in drm_sched_job_add_resv_dependencies When adding dependencies with drm_sched_job_add_dependency(), that
function consumes the fence reference both on success and failure, so in the latter case the
dma_fence_put() on the error path (xarray failed to expand) is a double free. Interestingly this bug
appears to have been present ever since commit ebd5f74255b9 ("drm/sched: Add dependency tracking"), since
the code back then looked like this: drm_sched_job_add_implicit_dependencies(): ... for (i = 0; i <
fence_count; i++) { ret = drm_sched_job_add_dependency(job, fences[i]); if (ret) break; } for (; i <
fence_count; i++) dma_fence_put(fences[i]); Which means for the failing 'i' the dma_fence_put was already
a double free. Possibly there were no users at that time, or the test cases were insufficient to hit it.
The bug was then only noticed and fixed after commit 9c2ba265352a ("drm/scheduler: use new iterator in
drm_sched_job_add_implicit_dependencies v2") landed, with its fixup of commit 4eaf02d6076c
("drm/scheduler: fix drm_sched_job_add_implicit_dependencies"). At that point it was a slightly different
flavour of a double free, which commit 963d0b356935 ("drm/scheduler: fix
drm_sched_job_add_implicit_dependencies harder") noticed and attempted to fix. But it only moved the
double free from happening inside the drm_sched_job_add_dependency(), when releasing the reference not yet
obtained, to the caller, when releasing the reference already released by the former in the failure case.
As such it is not easy to identify the right target for the fixes tag so lets keep it simple and just
continue the chain. While fixing we also improve the comment and explain the reason for taking the
reference and not dropping it. (CVE-2025-40096)

Solution

Update the linux library and its related packages to version 6.1.158-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-40096

Plugin Details

Severity: High

ID: 463257

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.47

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40096

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/30/2025

Vulnerability Publication Date: 10/30/2025

Reference Information

CVE: CVE-2025-40096