Echo: linux: security update to 6.8.11-1

medium Tenable Self-Hosted Container Security Plugin ID 455228

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: reset ptes when
close() for wr-protected ones Userfaultfd unregister includes a step to remove wr-protect bits from all
the relevant pgtable entries, but that only covered an explicit UFFDIO_UNREGISTER ioctl, not a close() on
the userfaultfd itself. Cover that too. This fixes a WARN trace. The only user visible side effect is the
user can observe leftover wr-protect bits even if the user close()ed on an userfaultfd when releasing the
last reference of it. However hopefully that should be harmless, and nothing bad should happen even if so.
This change is now more important after the recent page-table-check patch we merged in mm-unstable
(446dd9ad37d0 ("mm/page_table_check: support userfault wr-protect entries")), as we'll do sanity check on
uffd-wp bits without vma context. So it's better if we can 100% guarantee no uffd-wp bit leftovers, to
make sure each report will be valid. (CVE-2024-36881)

Solution

Update the linux library and its related packages to version 6.8.11-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-36881

Plugin Details

Severity: Medium

ID: 455228

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.48

CVSS v2

Risk Factor: Medium

Base Score: 4.5

Temporal Score: 3.3

Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:N/A:C

CVSS Score Source: CVE-2024-36881

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 5/30/2024

Reference Information

CVE: CVE-2024-36881