Echo: linux: security update to 6.1.153-1

medium Tenable Cloud Security Plugin ID 465901

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: comedi: Fix use of uninitialized
memory in do_insn_ioctl() and do_insnlist_ioctl() syzbot reports a KMSAN kernel-infoleak in
`do_insn_ioctl()`. A kernel buffer is allocated to hold `insn->n` samples (each of which is an `unsigned
int`). For some instruction types, `insn->n` samples are copied back to user-space, unless an error code
is being returned. The problem is that not all the instruction handlers that need to return data to
userspace fill in the whole `insn->n` samples, so that there is an information leak. There is a similar
syzbot report for `do_insnlist_ioctl()`, although it does not have a reproducer for it at the time of
writing. One culprit is `insn_rw_emulate_bits()` which is used as the handler for `INSN_READ` or
`INSN_WRITE` instructions for subdevices that do not have a specific handler for that instruction, but do
have an `INSN_BITS` handler. For `INSN_READ` it only fills in at most 1 sample, so if `insn->n` is greater
than 1, the remaining `insn->n - 1` samples copied to userspace will be uninitialized kernel data. Another
culprit is `vm80xx_ai_insn_read()` in the "vm80xx" driver. It never returns an error, even if it fails to
fill the buffer. Fix it in `do_insn_ioctl()` and `do_insnlist_ioctl()` by making sure that uninitialized
parts of the allocated buffer are zeroed before handling each instruction. Thanks to Arnaud Lecomte for
their fix to `do_insn_ioctl()`. That fix replaced the call to `kmalloc_array()` with `kcalloc()`, but it
is not always necessary to clear the whole buffer. (CVE-2025-39684)

Solution

Update the linux library and its related packages to version 6.1.153-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-39684

Plugin Details

Severity: Medium

ID: 465901

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.15

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-39684

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 9/5/2025

Reference Information

CVE: CVE-2025-39684