Echo: linux: security update to 6.1.176-1

high Tenable Self-Hosted Container Security Plugin ID 459198

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: misc: ibmasm: fix OOB MMIO read in
ibmasm_handle_mouse_interrupt() ibmasm_handle_mouse_interrupt() performs an out-of-bounds MMIO read when
the queue reader or writer index from hardware exceeds REMOTE_QUEUE_SIZE (60). A compromised service
processor can trigger this by writing an out-of-range value to the reader or writer MMIO register before
asserting an interrupt. Since writer is re-read from hardware on every loop iteration, it can also be set
to an out-of-range value after the loop has already started. The root cause is that get_queue_reader() and
get_queue_writer() return raw readl() values that are passed directly into get_queue_entry(), which
computes: queue_begin + reader * sizeof(struct remote_input) with no bounds check. This unchecked MMIO
address is then passed to memcpy_fromio(), reading 8 bytes from unintended device registers. For
sufficiently large values the address falls outside the PCI BAR mapping entirely, triggering a machine
check exception. Fix by checking both indices against REMOTE_QUEUE_SIZE at the top of the loop body,
before any call to get_queue_entry(). On an out-of-range value, reset the reader register to 0 via
set_queue_reader() before breaking, so that normal queue operation can resume if the corrupted hardware
state is transient. (CVE-2026-46022)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-46022

Plugin Details

Severity: High

ID: 459198

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.65

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2026-46022

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/27/2026

Reference Information

CVE: CVE-2026-46022