Echo: linux: security update to 6.1.176-1

medium Tenable Cloud Security Plugin ID 464995

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: hamradio: 6pack: fix uninit-value
in sixpack_receive_buf sixpack_receive_buf() does not properly skip bytes with TTY error flags. The while
loop iterates through the flags buffer but never advances the data pointer (cp), and passes the original
count (including error bytes) to sixpack_decode(). This causes sixpack_decode() to process bytes that
should have been skipped due to TTY errors. The TTY layer does not guarantee that cp[i] holds a meaningful
value when fp[i] is set, so passing those positions to sixpack_decode() results in KMSAN reporting an
uninit-value read. Fix this by processing bytes one at a time, advancing cp on each iteration, and only
passing valid (non-error) bytes to sixpack_decode(). This matches the pattern used by slip_receive_buf()
and mkiss_receive_buf() for the same purpose. (CVE-2026-53082)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-53082

Plugin Details

Severity: Medium

ID: 464995

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-53082

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/25/2026

Vulnerability Publication Date: 6/3/2026

Reference Information

CVE: CVE-2026-53082