Echo: linux: security update to 6.1.133-1

medium Tenable Self-Hosted Container Security Plugin ID 460737

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Consistently treat
platform_max as control value This reverts commit 9bdd10d57a88 ("ASoC: ops: Shift tested values in
snd_soc_put_volsw() by +min"), and makes some additional related updates. There are two ways the
platform_max could be interpreted; the maximum register value, or the maximum value the control can be set
to. The patch moved from treating the value as a control value to a register one. When the patch was
applied it was technically correct as snd_soc_limit_volume() also used the register interpretation.
However, even then most of the other usages treated platform_max as a control value, and
snd_soc_limit_volume() has since been updated to also do so in commit fb9ad24485087 ("ASoC: ops: add
correct range check for limiting volume"). That patch however, missed updating snd_soc_put_volsw() back to
the control interpretation, and fixing snd_soc_info_volsw_range(). The control interpretation makes more
sense as limiting is typically done from the machine driver, so it is appropriate to use the customer
facing representation rather than the internal codec representation. Update all the code to consistently
use this interpretation of platform_max. Finally, also add some comments to the soc_mixer_control struct
to hopefully avoid further patches switching between the two approaches. (CVE-2025-37889)

Solution

Update the linux library and its related packages to version 6.1.133-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-37889

Plugin Details

Severity: Medium

ID: 460737

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-37889

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 4/24/2025

Reference Information

CVE: CVE-2025-37889