Echo: linux: security update to 6.8.11-1

medium Tenable Self-Hosted Container Security Plugin ID 459780

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: sync all devices to wait
all processes being evicted If there are more than one device doing reset in parallel, the first device
will call kfd_suspend_all_processes() to evict all processes on all devices, this call takes time to
finish. other device will start reset and recover without waiting. if the process has not been evicted
before doing recover, it will be restored, then caused page fault. (CVE-2024-36949)

Solution

Update the linux library and its related packages to version 6.8.11-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-36949

Plugin Details

Severity: Medium

ID: 459780

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-36949

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 5/30/2024

Reference Information

CVE: CVE-2024-36949