Echo: linux: security update to 6.1.162-1

high Tenable Self-Hosted Container Security Plugin ID 455409

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xfrm: delete x->tunnel as we delete x
The ipcomp fallback tunnels currently get deleted (from the various lists and hashtables) as the last user
state that needed that fallback is destroyed (not deleted). If a reference to that user state still
exists, the fallback state will remain on the hashtables/lists, triggering the WARN in xfrm_state_fini.
Because of those remaining references, the fix in commit f75a2804da39 ("xfrm: destroy xfrm_state
synchronously on net exit path") is not complete. We recently fixed one such situation in TCP due to
defered freeing of skbs (commit 9b6412e6979f ("tcp: drop secpath at the same time as we currently drop
dst")). This can also happen due to IP reassembly: skbs with a secpath remain on the reassembly queue
until netns destruction. If we can't guarantee that the queues are flushed by the time xfrm_state_fini
runs, there may still be references to a (user) xfrm_state, preventing the timely deletion of the
corresponding fallback state. Instead of chasing each instance of skbs holding a secpath one by one, this
patch fixes the issue directly within xfrm, by deleting the fallback state as soon as the last user state
depending on it has been deleted. Destruction will still happen when the final reference is dropped. A
separate lockdep class for the fallback state is required since we're going to lock x->tunnel while x is
locked. (CVE-2025-40215)

Solution

Update the linux library and its related packages to version 6.1.162-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-40215

Plugin Details

Severity: High

ID: 455409

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40215

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/7/2025

Vulnerability Publication Date: 12/4/2025

Reference Information

CVE: CVE-2025-40215