Echo: linux: security update to 6.1.170-1

high Tenable Self-Hosted Container Security Plugin ID 455343

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free in
pm8001_queue_command() Commit e29c47fe8946 ("scsi: pm8001: Simplify pm8001_task_exec()") refactors
pm8001_queue_command(), however it introduces a potential cause of a double free scenario when it changes
the function to return -ENODEV in case of phy down/device gone state. In this path, pm8001_queue_command()
updates task status and calls task_done to indicate to upper layer that the task has been handled.
However, this also frees the underlying SAS task. A -ENODEV is then returned to the caller. When libsas
sas_ata_qc_issue() receives this error value, it assumes the task wasn't handled/queued by LLDD and
proceeds to clean up and free the task again, resulting in a double free. Since pm8001_queue_command()
handles the SAS task in this case, it should return 0 to the caller indicating that the task has been
handled. (CVE-2026-23306)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-23306

Plugin Details

Severity: High

ID: 455343

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.03

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-23306

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 3/25/2026

Reference Information

CVE: CVE-2026-23306