Echo: linux: security update to 6.1.170-1

high Tenable Self-Hosted Container Security Plugin ID 460887

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate
L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fixed
l2cap_info_rsp header (type + result, 4 bytes) but then reads rsp->data without verifying that the payload
is present: - L2CAP_IT_FEAT_MASK calls get_unaligned_le32(rsp->data), which reads 4 bytes past the header
(needs cmd_len >= 8). - L2CAP_IT_FIXED_CHAN reads rsp->data[0], 1 byte past the header (needs cmd_len >=
5). A truncated L2CAP_INFO_RSP with result == L2CAP_IR_SUCCESS triggers an out-of-bounds read of adjacent
skb data. Guard each data access with the required payload length check. If the payload is too short, skip
the read and let the state machine complete with safe defaults (feat_mask and remote_fixed_chan remain
zero from kzalloc), so the info timer cleanup and l2cap_conn_start() still run and the connection is not
stalled. (CVE-2026-31393)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-31393

Plugin Details

Severity: High

ID: 460887

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.31

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:A/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-31393

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 4/3/2026

Reference Information

CVE: CVE-2026-31393