Echo: linux: security update to 6.12.69-1

critical Tenable Self-Hosted Container Security Plugin ID 459378

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in
vfs_cache ksmbd maintains delete-on-close and pending-delete state in ksmbd_inode->m_flags. In vfs_cache.c
this field is accessed under inconsistent locking: some paths read and modify m_flags under ci->m_lock
while others do so without taking the lock at all. Examples: - ksmbd_query_inode_status() and
__ksmbd_inode_close() use ci->m_lock when checking or updating m_flags. - ksmbd_inode_pending_delete(),
ksmbd_set_inode_pending_delete(), ksmbd_clear_inode_pending_delete() and ksmbd_fd_set_delete_on_close()
used to read and modify m_flags without ci->m_lock. This creates a potential data race on m_flags when
multiple threads open, close and delete the same file concurrently. In the worst case delete-on-close and
pending-delete bits can be lost or observed in an inconsistent state, leading to confusing delete
semantics (files that stay on disk after delete-on-close, or files that disappear while still in use). Fix
it by: - Making ksmbd_query_inode_status() look at m_flags under ci->m_lock after dropping
inode_hash_lock. - Adding ci->m_lock protection to all helpers that read or modify m_flags
(ksmbd_inode_pending_delete(), ksmbd_set_inode_pending_delete(), ksmbd_clear_inode_pending_delete(),
ksmbd_fd_set_delete_on_close()). - Keeping the existing ci->m_lock protection in __ksmbd_inode_close(),
and moving the actual unlink/xattr removal outside the lock. This unifies the locking around m_flags and
removes the data race while preserving the existing delete-on-close behaviour. (CVE-2025-68809)

Solution

Update the linux library and its related packages to version 6.12.69-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68809

Plugin Details

Severity: Critical

ID: 459378

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.61

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2025-68809

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2026

Vulnerability Publication Date: 1/13/2026

Reference Information

CVE: CVE-2025-68809