Echo: linux: security update to 6.1.170-1

medium Tenable Cloud Security Plugin ID 464709

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: comedi: dt2815: add hardware detection
to prevent crash The dt2815 driver crashes when attached to I/O ports without actual hardware present.
This occurs because syzkaller or users can attach the driver to arbitrary I/O addresses via
COMEDI_DEVCONFIG ioctl. When no hardware exists at the specified port, inb() operations return 0xff
(floating bus), but outb() operations can trigger page faults due to undefined behavior, especially under
race conditions: BUG: unable to handle page fault for address: 000000007fffff90 #PF: supervisor write
access in kernel mode #PF: error_code(0x0002) - not-present page RIP: 0010:dt2815_attach+0x6e0/0x1110 Add
hardware detection by reading the status register before attempting any write operations. If the read
returns 0xff, assume no hardware is present and fail the attach with -ENODEV. This prevents crashes from
outb() operations on non-existent hardware. (CVE-2026-31751)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-31751

Plugin Details

Severity: Medium

ID: 464709

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-31751

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/2/2026

Vulnerability Publication Date: 4/23/2026

Reference Information

CVE: CVE-2026-31751