Echo: linux: security update to 6.8.9-1

medium Tenable Self-Hosted Container Security Plugin ID 460399

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: support deferring bpf_link
dealloc to after RCU grace period BPF link for some program types is passed as a "context" which can be
used by those BPF programs to look up additional information. E.g., for multi-kprobes and multi-uprobes,
link is used to fetch BPF cookie values. Because of this runtime dependency, when bpf_link refcnt drops to
zero there could still be active BPF programs running accessing link data. This patch adds generic support
to defer bpf_link dealloc callback to after RCU GP, if requested. This is done by exposing two different
deallocation callbacks, one synchronous and one deferred. If deferred one is provided, bpf_link_free()
will schedule dealloc_deferred() callback to happen after RCU GP. BPF is using two flavors of RCU:
"classic" non-sleepable one and RCU tasks trace one. The latter is used when sleepable BPF programs are
used. bpf_link_free() accommodates that by checking underlying BPF program's sleepable flag, and goes
either through normal RCU GP only for non-sleepable, or through RCU tasks trace GP *and* then normal RCU
GP (taking into account rcu_trace_implies_rcu_gp() optimization), if BPF program is sleepable. We use this
for multi-kprobe and multi-uprobe links, which dereference link during program run. We also preventively
switch raw_tp link to use deferred dealloc callback, as upcoming changes in bpf-next tree expose raw_tp
link data (specifically, cookie value) to BPF program at runtime as well. (CVE-2024-35860)

Solution

Update the linux library and its related packages to version 6.8.9-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-35860

Plugin Details

Severity: Medium

ID: 460399

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-35860

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 5/19/2024

Reference Information

CVE: CVE-2024-35860