Echo: linux: security update to 6.1.176-1

high Tenable Cloud Security Plugin ID 464793

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned
originator pointers in BAT IV BAT IV keeps the last-hop neighbor address in each neigh_node, but some
paths also cache an originator pointer derived from a temporary lookup. That pointer is not owned by the
neigh_node and may no longer refer to a live originator entry after purge handling runs. Stop storing the
auxiliary originator pointer in the BAT IV neighbor state. When BAT IV needs the neighbor originator data,
resolve it from the stored neighbor address and drop the reference again after use. [sven: avoid bonding
logic for outgoing OGM] (CVE-2026-46238)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-46238

Plugin Details

Severity: High

ID: 464793

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.14

CVSS v2

Risk Factor: High

Base Score: 8.3

Temporal Score: 6.1

Vector: CVSS2#AV:A/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-46238

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/28/2026

Reference Information

CVE: CVE-2026-46238