Echo: linux: security update to 6.1.147-1

medium Tenable Self-Hosted Container Security Plugin ID 461336

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: phy: mscc: Fix memory leak when
using one step timestamping Fix memory leak when running one-step timestamping. When running one-step sync
timestamping, the HW is configured to insert the TX time into the frame, so there is no reason to keep the
skb anymore. As in this case the HW will never generate an interrupt to say that the frame was
timestamped, then the frame will never released. Fix this by freeing the frame in case of one-step
timestamping. (CVE-2025-38148)

Solution

Update the linux library and its related packages to version 6.1.147-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-38148

Plugin Details

Severity: Medium

ID: 461336

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-38148

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 7/3/2025

Reference Information

CVE: CVE-2025-38148