Echo: linux: security update to 6.1.133-1

medium Tenable Self-Hosted Container Security Plugin ID 460524

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ppp: Fix KMSAN uninit-value warning
with bpf Syzbot caught an "KMSAN: uninit-value" warning [1], which is caused by the ppp driver not
initializing a 2-byte header when using socket filter. The following code can generate a PPP filter BPF
program: ''' struct bpf_program fp; pcap_t *handle; handle = pcap_open_dead(DLT_PPP_PPPD, 65535);
pcap_compile(handle, &fp, "ip and outbound", 0, 0); bpf_dump(&fp, 1); ''' Its output is: ''' (000) ldh [2]
(001) jeq #0x21 jt 2 jf 5 (002) ldb [0] (003) jeq #0x1 jt 4 jf 5 (004) ret #65535 (005) ret #0 ''' Wen can
find similar code at the following link: https://github.com/ppp-
project/ppp/blob/master/pppd/options.c#L1680 The maintainer of this code repository is also the original
maintainer of the ppp driver. As you can see the BPF program skips 2 bytes of data and then reads the
'Protocol' field to determine if it's an IP packet. Then it read the first byte of the first 2 bytes to
determine the direction. The issue is that only the first byte indicating direction is initialized in
current ppp driver code while the second byte is not initialized. For normal BPF programs generated by
libpcap, uninitialized data won't be used, so it's not a problem. However, for carefully crafted BPF
programs, such as those generated by syzkaller [2], which start reading from offset 0, the uninitialized
data will be used and caught by KMSAN. [1] https://syzkaller.appspot.com/bug?extid=853242d9c9917165d791
[2] https://syzkaller.appspot.com/text?tag=ReproC&x=11994913980000 (CVE-2025-21922)

Solution

Update the linux library and its related packages to version 6.1.133-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-21922

Plugin Details

Severity: Medium

ID: 460524

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-21922

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 3/20/2025

Reference Information

CVE: CVE-2025-21922