Echo: linux: security update to 6.1.176-1

medium Tenable Self-Hosted Container Security Plugin ID 458258

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Avoid WARN() for
symlink errors Using WARN() for showing the error of symlink creations don't give more information than
telling that something goes wrong, since the usual code path is a lregister callback from each control
element creation. More badly, the use of WARN() rather confuses fuzzer as if it were serious issues. This
patch downgrades the warning messages to use the normal dev_err() instead of WARN(). For making it
clearer, add the function name to the prefix, too. (CVE-2024-56657)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-56657

Plugin Details

Severity: Medium

ID: 458258

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-56657

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 12/27/2024

Reference Information

CVE: CVE-2024-56657