Echo: linux: security update to 6.1.176-1

medium Tenable Cloud Security Plugin ID 464955

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix heap leak in IEEE 1284
device ID via short response usblp_ctrl_msg() collapses the usb_control_msg() return value to 0/-errno,
discarding the actual number of bytes transferred. A broken printer can complete the GET_DEVICE_ID control
transfer short and the driver has no way to know. usblp_cache_device_id_string() reads the 2-byte big-
endian length prefix from the response and trusts it (clamped only to the buffer bounds). The buffer is
kmalloc(1024) at probe time. A device that sends exactly two bytes (e.g. 0x03 0xFF, claiming a 1023-byte
ID) leaves device_id_string[2..1022] holding stale kmalloc heap. That stale data is then exposed: - via
the ieee1284_id sysfs attribute (sprintf("%s", buf+2), truncated at the first NUL in the stale heap), and
- via the IOCNR_GET_DEVICE_ID ioctl, which copy_to_user()s the full claimed length regardless of NULs, up
to 1021 bytes of uninitialized heap, with the leak size chosen by the device. Fix this up by just zapping
the buffer with zeros before each request sent to the device. (CVE-2026-46151)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-46151

Plugin Details

Severity: Medium

ID: 464955

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-46151

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/28/2026

Reference Information

CVE: CVE-2026-46151