Echo: linux: security update to 6.1.176-1

high Tenable Self-Hosted Container Security Plugin ID 460376

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential null-ptr-deref
in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a
CRUSH map. When decoding this CRUSH map in crush_decode(), an array of max_buckets CRUSH buckets is
decoded, where some indices may not refer to actual buckets and are therefore set to NULL. The received
CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). When decoding a
crush_choose_arg_map, a series of choose_args for different buckets is decoded, with the bucket_index
being read from the incoming message. It is only checked that the bucket index does not exceed
max_buckets, but not that it doesn't point to an index with a NULL bucket. If a (potentially corrupted)
message contains a crush_choose_arg_map including such a bucket_index, a null pointer dereference may
occur in the subsequent processing when attempting to access the bucket with the given index. This patch
fixes the issue by extending the affected check. Now, it is only attempted to access the bucket if it is
not NULL. (CVE-2026-52957)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-52957

Plugin Details

Severity: High

ID: 460376

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.77

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-52957

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/25/2026

Vulnerability Publication Date: 6/3/2026

Reference Information

CVE: CVE-2026-52957