Echo: linux: security update to 6.1.162-1

medium Tenable Self-Hosted Container Security Plugin ID 457144

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Fix VM_PAT handling when
fork() fails in copy_page_range() If track_pfn_copy() fails, we already added the dst VMA to the maple
tree. As fork() fails, we'll cleanup the maple tree, and stumble over the dst VMA for which we neither
performed any reservation nor copied any page tables. Consequently untrack_pfn() will see VM_PAT and try
obtaining the PAT information from the page table -- which fails because the page table was not copied.
The easiest fix would be to simply clear the VM_PAT flag of the dst VMA if track_pfn_copy() fails.
However, the whole thing is about "simply" clearing the VM_PAT flag is shaky as well: if we passed
track_pfn_copy() and performed a reservation, but copying the page tables fails, we'll simply clear the
VM_PAT flag, not properly undoing the reservation ... which is also wrong. So let's fix it properly: set
the VM_PAT flag only if the reservation succeeded (leaving it clear initially), and undo the reservation
if anything goes wrong while copying the page tables: clearing the VM_PAT flag after undoing the
reservation. Note that any copied page table entries will get zapped when the VMA will get removed later,
after copy_page_range() succeeded; as VM_PAT is not set then, we won't try cleaning VM_PAT up once more
and untrack_pfn() will be happy. Note that leaving these page tables in place without a reservation is not
a problem, as we are aborting fork(); this process will never run. A reproducer can trigger this usually
at the first try: https://gitlab.com/davidhildenbrand/scratchspace/-/raw/main/reproducers/pat_fork.c
WARNING: CPU: 26 PID: 11650 at arch/x86/mm/pat/memtype.c:983 get_pat_info+0xf6/0x110 Modules linked in:
... CPU: 26 UID: 0 PID: 11650 Comm: repro3 Not tainted 6.12.0-rc5+ #92 Hardware name: QEMU Standard PC
(Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 RIP: 0010:get_pat_info+0xf6/0x110 ... Call Trace: <TASK>
... untrack_pfn+0x52/0x110 unmap_single_vma+0xa6/0xe0 unmap_vmas+0x105/0x1f0 exit_mmap+0xf6/0x460
__mmput+0x4b/0x120 copy_process+0x1bf6/0x2aa0 kernel_clone+0xab/0x440 __do_sys_clone+0x66/0x90
do_syscall_64+0x95/0x180 Likely this case was missed in: d155df53f310 ("x86/mm/pat: clear VM_PAT if
copy_p4d_range failed") ... and instead of undoing the reservation we simply cleared the VM_PAT flag. Keep
the documentation of these functions in include/linux/pgtable.h, one place is more than sufficient -- we
should clean that up for the other functions like track_pfn_remap/untrack_pfn separately. (CVE-2025-22090)

Solution

Update the linux library and its related packages to version 6.1.162-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-22090

Plugin Details

Severity: Medium

ID: 457144

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-22090

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 4/16/2025

Reference Information

CVE: CVE-2025-22090