Echo: linux: security update to 6.12.69-1

high Tenable Self-Hosted Container Security Plugin ID 461281

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: phy: fsl-usb: Fix use-after-free
in delayed work during device removal The delayed work item otg_event is initialized in fsl_otg_conf() and
scheduled under two conditions: 1. When a host controller binds to the OTG controller. 2. When the USB ID
pin state changes (cable insertion/removal). A race condition occurs when the device is removed via
fsl_otg_remove(): the fsl_otg instance may be freed while the delayed work is still pending or executing.
This leads to use-after-free when the work function fsl_otg_event() accesses the already freed memory. The
problematic scenario: (detach thread) | (delayed work) fsl_otg_remove() | kfree(fsl_otg_dev) //FREE|
fsl_otg_event() | og = container_of(...) //USE | og-> //USE Fix this by calling
disable_delayed_work_sync() in fsl_otg_remove() before deallocating the fsl_otg structure. This ensures
the delayed work is properly canceled and completes execution prior to memory deallocation. This bug was
identified through static analysis. (CVE-2025-68781)

Solution

Update the linux library and its related packages to version 6.12.69-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68781

Plugin Details

Severity: High

ID: 461281

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.47

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 5.1

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68781

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2026

Vulnerability Publication Date: 1/13/2026

Reference Information

CVE: CVE-2025-68781