Echo: linux: security update to 6.1.176-1

medium Tenable Self-Hosted Container Security Plugin ID 460159

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value by
validating catalog record size Syzbot reported a KMSAN uninit-value issue in hfsplus_strcasecmp(). The
root cause is that hfs_brec_read() doesn't validate that the on-disk record size matches the expected size
for the record type being read. When mounting a corrupted filesystem, hfs_brec_read() may read less data
than expected. For example, when reading a catalog thread record, the debug output showed:
HFSPLUS_BREC_READ: rec_len=520, fd->entrylength=26 HFSPLUS_BREC_READ: WARNING - entrylength (26) < rec_len
(520) - PARTIAL READ! hfs_brec_read() only validates that entrylength is not greater than the buffer size,
but doesn't check if it's less than expected. It successfully reads 26 bytes into a 520-byte structure and
returns success, leaving 494 bytes uninitialized. This uninitialized data in tmp.thread.nodeName then gets
copied by hfsplus_cat_build_key_uni() and used by hfsplus_strcasecmp(), triggering the KMSAN warning when
the uninitialized bytes are used as array indices in case_fold(). Fix by introducing
hfsplus_brec_read_cat() wrapper that: 1. Calls hfs_brec_read() to read the data 2. Validates the record
size based on the type field: - Fixed size for folder and file records - Variable size for thread records
(depends on string length) 3. Returns -EIO if size doesn't match expected For thread records, check
against HFSPLUS_MIN_THREAD_SZ before reading nodeName.length to avoid reading uninitialized data at call
sites that don't zero-initialize the entry structure. Also initialize the tmp variable in
hfsplus_find_cat() as defensive programming to ensure no uninitialized data even if validation is
bypassed. (CVE-2026-46169)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-46169

Plugin Details

Severity: Medium

ID: 460159

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-46169

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/28/2026

Reference Information

CVE: CVE-2026-46169