Echo: linux: security update to 6.1.164-1

medium Tenable Self-Hosted Container Security Plugin ID 459118

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: nilfs2: Fix potential block overflow
that cause system hang When a user executes the FITRIM command, an underflow can occur when calculating
nblocks if end_block is too small. Since nblocks is of type sector_t, which is u64, a negative nblocks
value will become a very large positive integer. This ultimately leads to the block layer function
__blkdev_issue_discard() taking an excessively long time to process the bio chain, and the ns_segctor_sem
lock remains held for a long period. This prevents other tasks from acquiring the ns_segctor_sem lock,
resulting in the hang reported by syzbot in [1]. If the ending block is too small, typically if it is
smaller than 4KiB range, depending on the usage of the segment 0, it may be possible to attempt a discard
request beyond the device size causing the hang. Exiting successfully and assign the discarded size (0 in
this case) to range->len. Although the start and len values in the user input range are too small, a
conservative strategy is adopted here to safely ignore them, which is equivalent to a no-op; it will not
perform any trimming and will not throw an error. [1] task:segctord state:D stack:28968 pid:6093 tgid:6093
ppid:2 task_flags:0x200040 flags:0x00080000 Call Trace: rwbase_write_lock+0x3dd/0x750
kernel/locking/rwbase_rt.c:272 nilfs_transaction_lock+0x253/0x4c0 fs/nilfs2/segment.c:357
nilfs_segctor_thread_construct fs/nilfs2/segment.c:2569 [inline] nilfs_segctor_thread+0x6ec/0xe00
fs/nilfs2/segment.c:2684 [ryusuke: corrected part of the commit message about the consequences]
(CVE-2025-71237)

Solution

Update the linux library and its related packages to version 6.1.164-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-71237

Plugin Details

Severity: Medium

ID: 459118

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.49

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-71237

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/19/2026

Vulnerability Publication Date: 2/18/2026

Reference Information

CVE: CVE-2025-71237