Echo: linux: security update to 6.12.5-1

medium Tenable Self-Hosted Container Security Plugin ID 457894

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to drop all discards after
creating snapshot on lvm device Piergiorgio reported a bug in bugzilla as below: ------------[ cut here
]------------ WARNING: CPU: 2 PID: 969 at fs/f2fs/segment.c:1330 RIP:
0010:__submit_discard_cmd+0x27d/0x400 [f2fs] Call Trace: __issue_discard_cmd+0x1ca/0x350 [f2fs]
issue_discard_thread+0x191/0x480 [f2fs] kthread+0xcf/0x100 ret_from_fork+0x31/0x50
ret_from_fork_asm+0x1a/0x30 w/ below testcase, it can reproduce this bug quickly: - pvcreate /dev/vdb -
vgcreate myvg1 /dev/vdb - lvcreate -L 1024m -n mylv1 myvg1 - mount /dev/myvg1/mylv1 /mnt/f2fs - dd
if=/dev/zero of=/mnt/f2fs/file bs=1M count=20 - sync - rm /mnt/f2fs/file - sync - lvcreate -L 1024m -s -n
mylv1-snapshot /dev/myvg1/mylv1 - umount /mnt/f2fs The root cause is: it will update discard_max_bytes of
mounted lvm device to zero after creating snapshot on this lvm device, then, __submit_discard_cmd() will
pass parameter @nr_sects w/ zero value to __blkdev_issue_discard(), it returns a NULL bio pointer, result
in panic. This patch changes as below for fixing: 1. Let's drop all remained discards in f2fs_unfreeze()
if snapshot of lvm device is created. 2. Checking discard_max_bytes before submitting discard during
__submit_discard_cmd(). (CVE-2024-56565)

Solution

Update the linux library and its related packages to version 6.12.5-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-56565

Plugin Details

Severity: Medium

ID: 457894

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.26

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-56565

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 12/27/2024

Reference Information

CVE: CVE-2024-56565