Echo: linux: security update to 6.1.135-1

medium Tenable Cloud Security Plugin ID 465309

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: HID: pidff: Fix null pointer
dereference in pidff_find_fields This function triggered a null pointer dereference if used to search for
a report that isn't implemented on the device. This happened both for optional and required reports alike.
The same logic was applied to pidff_find_special_field and although pidff_init_fields should return an
error earlier if one of the required reports is missing, future modifications could change this logic and
resurface this possible null pointer dereference again. LKML bug report: https://lore.kernel.org/all/CAL-
[email protected] (CVE-2025-37862)

Solution

Update the linux library and its related packages to version 6.1.135-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-37862

Plugin Details

Severity: Medium

ID: 465309

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-37862

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 5/5/2025

Reference Information

CVE: CVE-2025-37862