Echo: linux: security update to 6.1.147-1

high Tenable Cloud Security Plugin ID 464555

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between
vmci_host_setup_notify and vmci_ctx_unset_notify During our test, it is found that a warning can be
trigger in try_grab_folio as follow: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 1678 at
mm/gup.c:147 try_grab_folio+0x106/0x130 Modules linked in: CPU: 0 UID: 0 PID: 1678 Comm: syz.3.31 Not
tainted 6.15.0-rc5 #163 PREEMPT(undef) RIP: 0010:try_grab_folio+0x106/0x130 Call Trace: <TASK>
follow_huge_pmd+0x240/0x8e0 follow_pmd_mask.constprop.0.isra.0+0x40b/0x5c0
follow_pud_mask.constprop.0.isra.0+0x14a/0x170 follow_page_mask+0x1c2/0x1f0 __get_user_pages+0x176/0x950
__gup_longterm_locked+0x15b/0x1060 ? gup_fast+0x120/0x1f0 gup_fast_fallback+0x17e/0x230
get_user_pages_fast+0x5f/0x80 vmci_host_unlocked_ioctl+0x21c/0xf80 RIP: 0033:0x54d2cd ---[ end trace
0000000000000000 ]--- Digging into the source, context->notify_page may init by get_user_pages_fast and
can be seen in vmci_ctx_unset_notify which will try to put_page. However get_user_pages_fast is not
finished here and lead to following try_grab_folio warning. The race condition is shown as follow: cpu0
cpu1 vmci_host_do_set_notify vmci_host_setup_notify get_user_pages_fast(uva, 1, FOLL_WRITE,
&context->notify_page); lockless_pages_from_mm gup_pgd_range gup_huge_pmd // update &context->notify_page
vmci_host_do_set_notify vmci_ctx_unset_notify notify_page = context->notify_page; if (notify_page)
put_page(notify_page); // page is freed __gup_longterm_locked __get_user_pages follow_trans_huge_pmd
try_grab_folio // warn here To slove this, use local variable page to make notify_page can be seen after
finish get_user_pages_fast. (CVE-2025-38102)

Solution

Update the linux library and its related packages to version 6.1.147-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-38102

Plugin Details

Severity: High

ID: 464555

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.38

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.4

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-38102

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 7/3/2025

Reference Information

CVE: CVE-2025-38102