Echo: linux: security update to 6.9.7-1

medium Tenable Cloud Security Plugin ID 464374

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: platform/x86: x86-android-tablets:
Unregister devices in reverse order Not all subsystems support a device getting removed while there are
still consumers of the device with a reference to the device. One example of this is the regulator
subsystem. If a regulator gets unregistered while there are still drivers holding a reference a WARN() at
drivers/regulator/core.c:5829 triggers, e.g.: WARNING: CPU: 1 PID: 1587 at drivers/regulator/core.c:5829
regulator_unregister Hardware name: Intel Corp. VALLEYVIEW C0 PLATFORM/BYT-T FFD8, BIOS
BLADE_21.X64.0005.R00.1504101516 FFD8_X64_R_2015_04_10_1516 04/10/2015 RIP: 0010:regulator_unregister Call
Trace: <TASK> regulator_unregister devres_release_group i2c_device_remove device_release_driver_internal
bus_remove_device device_del device_unregister x86_android_tablet_remove On the Lenovo Yoga Tablet 2
series the bq24190 charger chip also provides a 5V boost converter output for powering USB devices
connected to the micro USB port, the bq24190-charger driver exports this as a Vbus regulator. On the 830
(8") and 1050 ("10") models this regulator is controlled by a platform_device and
x86_android_tablet_remove() removes platform_device-s before i2c_clients so the consumer gets removed
first. But on the 1380 (13") model there is a lc824206xa micro-USB switch connected over I2C and the
extcon driver for that controls the regulator. The bq24190 i2c-client *must* be registered first, because
that creates the regulator with the lc824206xa listed as its consumer. If the regulator has not been
registered yet the lc824206xa driver will end up getting a dummy regulator. Since in this case both the
regulator provider and consumer are I2C devices, the only way to ensure that the consumer is unregistered
first is to unregister the I2C devices in reverse order of in which they were created. For consistency and
to avoid similar problems in the future change x86_android_tablet_remove() to unregister all device types
in reverse order. (CVE-2024-40975)

Solution

Update the linux library and its related packages to version 6.9.7-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-40975

Plugin Details

Severity: Medium

ID: 464374

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.16

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-40975

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 7/12/2024

Reference Information

CVE: CVE-2024-40975