Echo: linux: security update to 6.1.162-1

high Tenable Self-Hosted Container Security Plugin ID 455610

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix missing hfs_bnode_get()
in __hfs_bnode_create When sync() and link() are called concurrently, both threads may enter
hfs_bnode_find() without finding the node in the hash table and proceed to create it. Thread A:
hfsplus_write_inode() -> hfsplus_write_system_inode() -> hfs_btree_write() -> hfs_bnode_find(tree, 0) ->
__hfs_bnode_create(tree, 0) Thread B: hfsplus_create_cat() -> hfs_brec_insert() -> hfs_bnode_split() ->
hfs_bmap_alloc() -> hfs_bnode_find(tree, 0) -> __hfs_bnode_create(tree, 0) In this case, thread A creates
the bnode, sets refcnt=1, and hashes it. Thread B also tries to create the same bnode, notices it has
already been inserted, drops its own instance, and uses the hashed one without getting the node. ``` node2
= hfs_bnode_findhash(tree, cnid); if (!node2) { <- Thread A hash = hfs_bnode_hash(cnid); node->next_hash =
tree->node_hash[hash]; tree->node_hash[hash] = node; tree->node_hash_cnt++; } else { <- Thread B
spin_unlock(&tree->hash_lock); kfree(node); wait_event(node2->lock_wq, !test_bit(HFS_BNODE_NEW,
&node2->flags)); return node2; } ``` However, hfs_bnode_find() requires each call to take a reference.
Here both threads end up setting refcnt=1. When they later put the node, this triggers:
BUG_ON(!atomic_read(&node->refcnt)) In this scenario, Thread B in fact finds the node in the hash table
rather than creating a new one, and thus must take a reference. Fix this by calling hfs_bnode_get() when
reusing a bnode newly created by another thread to ensure the refcount is updated correctly. A similar bug
was fixed in HFS long ago in commit a9dc087fd3c4 ("fix missing hfs_bnode_get() in __hfs_bnode_create") but
the same issue remained in HFS+ until now. (CVE-2025-68774)

Solution

Update the linux library and its related packages to version 6.1.162-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68774

Plugin Details

Severity: High

ID: 455610

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.46

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-68774

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2026

Vulnerability Publication Date: 1/13/2026

Reference Information

CVE: CVE-2025-68774