Echo: linux: security update to 6.1.159-1

medium Tenable Self-Hosted Container Security Plugin ID 458456

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when
the uas device is remove during ongoing data transfer When a UAS device is unplugged during data transfer,
there is a probability of a system panic occurring. The root cause is an access to an invalid memory
address during URB callback handling. Specifically, this happens when the dma_direct_unmap_sg() function
is called within the usb_hcd_unmap_urb_for_dma() interface, but the sg->dma_address field is 0 and the sg
data structure has already been freed. The SCSI driver sends transfer commands by invoking
uas_queuecommand_lck() in uas.c, using the uas_submit_urbs() function to submit requests to USB. Within
the uas_submit_urbs() implementation, three URBs (sense_urb, data_urb, and cmd_urb) are sequentially
submitted. Device removal may occur at any point during uas_submit_urbs execution, which may result in URB
submission failure. However, some URBs might have been successfully submitted before the failure, and
uas_submit_urbs will return the -ENODEV error code in this case. The current error handling directly calls
scsi_done(). In the SCSI driver, this eventually triggers scsi_complete() to invoke scsi_end_request() for
releasing the sgtable. The successfully submitted URBs, when being unlinked to giveback, call
usb_hcd_unmap_urb_for_dma() in hcd.c, leading to exceptions during sg unmapping operations since the sg
data structure has already been freed. This patch modifies the error condition check in the
uas_submit_urbs() function. When a UAS device is removed but one or more URBs have already been
successfully submitted to USB, it avoids immediately invoking scsi_done() and save the cmnd to
devinfo->cmnd array. If the successfully submitted URBs is completed before devinfo->resetting being set,
then the scsi_done() function will be called within uas_try_complete() after all pending URB operations
are finalized. Otherwise, the scsi_done() function will be called within uas_zap_pending(), which is
executed after usb_kill_anchored_urbs(). The error handling only takes effect when uas_queuecommand_lck()
calls uas_submit_urbs() and returns the error value -ENODEV . In this case, the device is disconnected,
and the flow proceeds to uas_disconnect(), where uas_zap_pending() is invoked to call uas_try_complete().
(CVE-2025-68331)

Solution

Update the linux library and its related packages to version 6.1.159-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68331

Plugin Details

Severity: Medium

ID: 458456

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.49

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.4

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68331

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Temporal Score: 5.5

Vector: CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/23/2025

Vulnerability Publication Date: 12/9/2025

Reference Information

CVE: CVE-2025-68331