Echo: linux: security update to 6.1.170-1

medium Tenable Self-Hosted Container Security Plugin ID 459159

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null
dereference This patch fixes a possible null pointer dereference when this function is called from
request_lock() as lkb->lkb_resource is not assigned yet, only after validate_lock_args() by calling
attach_lkb(). Another issue is that a resource name could be a non printable bytearray and we cannot
assume to be ASCII coded. The log functionality is probably never being hit when DLM is used in normal way
and no debug logging is enabled. The null pointer dereference can only occur on a new created lkb that
does not have the resource assigned yet, it probably never hits the null pointer dereference but we should
be sure that other changes might not change this behaviour and we actually can hit the mentioned null
pointer dereference. In this patch we just drop the printout of the resource name, the lkb id is enough to
make a possible connection to a resource name if this exists. (CVE-2024-47809)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-47809

Plugin Details

Severity: Medium

ID: 459159

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-47809

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 1/11/2025

Reference Information

CVE: CVE-2024-47809