Echo: linux: security update to 6.12.41-1

medium Tenable Cloud Security Plugin ID 463949

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management
in ism_cmd() The s390x ISM device data sheet clearly states that only one request-response sequence is
allowable per ISM function at any point in time. Unfortunately as of today the s390/ism driver in Linux
does not honor that requirement. This patch aims to rectify that. This problem was discovered based on
Aliaksei's bug report which states that for certain workloads the ISM functions end up entering error
state (with PEC 2 as seen from the logs) after a while and as a consequence connections handled by the
respective function break, and for future connection requests the ISM device is not considered -- given it
is in a dysfunctional state. During further debugging PEC 3A was observed as well. A kernel message like [
1211.244319] zpci: 061a:00:00.0: Event 0x2 reports an error for PCI function 0x61a is a reliable indicator
of the stated function entering error state with PEC 2. Let me also point out that a kernel message like [
1211.244325] zpci: 061a:00:00.0: The ism driver bound to the device does not support error recovery is a
reliable indicator that the ISM function won't be auto-recovered because the ISM driver currently lacks
support for it. On a technical level, without this synchronization, commands (inputs to the FW) may be
partially or fully overwritten (corrupted) by another CPU trying to issue commands on the same function.
There is hard evidence that this can lead to DMB token values being used as DMB IOVAs, leading to PEC 2
PCI events indicating invalid DMA. But this is only one of the failure modes imaginable. In theory even
completely losing one command and executing another one twice and then trying to interpret the outputs as
if the command we intended to execute was actually executed and not the other one is also possible.
Frankly, I don't feel confident about providing an exhaustive list of possible consequences.
(CVE-2025-39726)

Solution

Update the linux library and its related packages to version 6.12.41-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-39726

Plugin Details

Severity: Medium

ID: 463949

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.29

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-39726

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 9/5/2025

Reference Information

CVE: CVE-2025-39726