Echo: linux: security update to 6.1.158-1

high Tenable Cloud Security Plugin ID 465400

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: kmsan: fix out-of-bounds access to
shadow memory Running sha224_kunit on a KMSAN-enabled kernel results in a crash in
kmsan_internal_set_shadow_origin(): BUG: unable to handle page fault for address: ffffbc3840291000 #PF:
supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 1810067 P4D 1810067
PUD 192d067 PMD 3c17067 PTE 0 Oops: 0000 [#1] SMP NOPTI CPU: 0 UID: 0 PID: 81 Comm: kunit_try_catch
Tainted: G N 6.17.0-rc3 #10 PREEMPT(voluntary) Tainted: [N]=TEST Hardware name: QEMU Standard PC (i440FX +
PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 RIP:
0010:kmsan_internal_set_shadow_origin+0x91/0x100 [...] Call Trace: <TASK> __msan_memset+0xee/0x1a0
sha224_final+0x9e/0x350 test_hash_buffer_overruns+0x46f/0x5f0 ? kmsan_get_shadow_origin_ptr+0x46/0xa0 ?
__pfx_test_hash_buffer_overruns+0x10/0x10 kunit_try_run_case+0x198/0xa00 This occurs when memset() is
called on a buffer that is not 4-byte aligned and extends to the end of a guard page, i.e. the next page
is unmapped. The bug is that the loop at the end of kmsan_internal_set_shadow_origin() accesses the wrong
shadow memory bytes when the address is not 4-byte aligned. Since each 4 bytes are associated with an
origin, it rounds the address and size so that it can access all the origins that contain the buffer.
However, when it checks the corresponding shadow bytes for a particular origin, it incorrectly uses the
original unrounded shadow address. This results in reads from shadow memory beyond the end of the buffer's
shadow memory, which crashes when that memory is not mapped. To fix this, correctly align the shadow
address before accessing the 4 shadow bytes corresponding to each origin. (CVE-2025-40008)

Solution

Update the linux library and its related packages to version 6.1.158-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-40008

Plugin Details

Severity: High

ID: 465400

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.29

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40008

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/20/2025

Vulnerability Publication Date: 10/14/2025

Reference Information

CVE: CVE-2025-40008