Echo: linux: security update to 6.12.43-1

medium Tenable Cloud Security Plugin ID 465788

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: shutdown driver when
hardware is unreliable In rare cases, ath10k may lose connection with the PCIe bus due to some unknown
reasons, which could further lead to system crashes during resuming due to watchdog timeout: ath10k_pci
0000:01:00.0: wmi command 20486 timeout, restarting hardware ath10k_pci 0000:01:00.0: already restarting
ath10k_pci 0000:01:00.0: failed to stop WMI vdev 0: -11 ath10k_pci 0000:01:00.0: failed to stop vdev 0:
-11 ieee80211 phy0: PM: **** DPM device timeout **** Call Trace: panic+0x125/0x315
dpm_watchdog_set+0x54/0x54 dpm_watchdog_handler+0x57/0x57 call_timer_fn+0x31/0x13c At this point, all WMI
commands will timeout and attempt to restart device. So set a threshold for consecutive restart failures.
If the threshold is exceeded, consider the hardware is unreliable and all ath10k operations should be
skipped to avoid system crash. fail_cont_count and pending_recovery are atomic variables, and do not
involve complex conditional logic. Therefore, even if recovery check and reconfig complete are executed
concurrently, the recovery mechanism will not be broken. Tested-on: QCA6174 hw3.2 PCI
WLAN.RM.4.4.1-00288-QCARMSWPZ-1 (CVE-2025-39746)

Solution

Update the linux library and its related packages to version 6.12.43-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-39746

Plugin Details

Severity: Medium

ID: 465788

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.48

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-39746

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 9/11/2025

Reference Information

CVE: CVE-2025-39746