Echo: linux: security update to 6.1.133-1

high Tenable Cloud Security Plugin ID 464440

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory
corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq.
This 'prev' pointer can originate from struct rq's leaf_cfs_rq_list, making the conversion invalid and
potentially leading to memory corruption. Depending on the relative positions of leaf_cfs_rq_list and the
task group (tg) pointer within the struct, this can cause a memory fault or access garbage data. The issue
arises in list_add_leaf_cfs_rq, where both cfs_rq->leaf_cfs_rq_list and rq->leaf_cfs_rq_list are added to
the same leaf list. Also, rq->tmp_alone_branch can be set to rq->leaf_cfs_rq_list. This adds a check `if
(prev == &rq->leaf_cfs_rq_list)` after the main conditional in child_cfs_rq_on_list. This ensures that the
container_of operation will convert a correct cfs_rq struct. This check is sufficient because only cfs_rqs
on the same CPU are added to the list, so verifying the 'prev' pointer against the current rq's list head
is enough. Fixes a potential memory corruption issue that due to current struct layout might not be
manifesting as a crash but could lead to unpredictable behavior when the layout changes. (CVE-2025-21919)

Solution

Update the linux library and its related packages to version 6.1.133-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-21919

Plugin Details

Severity: High

ID: 464440

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-21919

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 4/1/2025

Reference Information

CVE: CVE-2025-21919