Echo: linux: security update to 6.1.162-1

medium Tenable Cloud Security Plugin ID 463398

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to
supplier LEDs LED Backlight is a consumer of one or multiple LED class devices, but devlink is currently
unable to create correct supplier-producer links when the supplier is a class device. It creates instead a
link where the supplier is the parent of the expected device. One consequence is that removal order is not
correctly enforced. Issues happen for example with the following sections in a device tree overlay: // An
LED driver chip pca9632@62 { compatible = "nxp,pca9632"; reg = <0x62>; // ... addon_led_pwm: led-pwm@3 {
reg = <3>; label = "addon:led:pwm"; }; }; backlight-addon { compatible = "led-backlight"; leds =
<&addon_led_pwm>; brightness-levels = <255>; default-brightness-level = <255>; }; In this example, the
devlink should be created between the backlight-addon (consumer) and the pca9632@62 (supplier). Instead it
is created between the backlight-addon (consumer) and the parent of the pca9632@62, which is typically the
I2C bus adapter. On removal of the above overlay, the LED driver can be removed before the backlight
device, resulting in: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010
... Call trace: led_put+0xe0/0x140 devm_led_release+0x6c/0x98 Another way to reproduce the bug without any
device tree overlays is unbinding the LED class device (pca9632@62) before unbinding the consumer
(backlight-addon): echo 11-0062 >/sys/bus/i2c/drivers/leds-pca963x/unbind echo ...backlight-dock
>/sys/bus/platform/drivers/led-backlight/unbind Fix by adding a devlink between the consuming led-
backlight device and the supplying LED device, as other drivers and subsystems do as well.
(CVE-2025-68758)

Solution

Update the linux library and its related packages to version 6.1.162-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68758

Plugin Details

Severity: Medium

ID: 463398

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.42

CVSS v2

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:P/A:C

CVSS Score Source: CVE-2025-68758

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/5/2026

Vulnerability Publication Date: 1/5/2026

Reference Information

CVE: CVE-2025-68758