Echo: linux: security update to 6.1.133-1

medium Tenable Self-Hosted Container Security Plugin ID 461936

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: tracing: Fix bad hist from corrupting
named_triggers list The following commands causes a crash: ~# cd
/sys/kernel/tracing/events/rcu/rcu_callback ~# echo
'hist:name=bad:keys=common_pid:onmax(bogus).save(common_pid)' > trigger bash: echo: write error: Invalid
argument ~# echo 'hist:name=bad:keys=common_pid' > trigger Because the following occurs:
event_trigger_write() { trigger_process_regex() { event_hist_trigger_parse() { data =
event_trigger_alloc(..); event_trigger_register(.., data) { cmd_ops->reg(.., data, ..)
[hist_register_trigger()] { data->ops->init() [event_hist_trigger_init()] { save_named_trigger(name, data)
{ list_add(&data->named_list, &named_triggers); } } } } ret = create_actions(); (return -EINVAL) if (ret)
goto out_unreg; [..] ret = hist_trigger_enable(data, ...) { list_add_tail_rcu(&data->list,
&file->triggers); <<<---- SKIPPED!!! (this is important!) [..] out_unreg: event_hist_unregister(.., data)
{ cmd_ops->unreg(.., data, ..) [hist_unregister_trigger()] { list_for_each_entry(iter, &file->triggers,
list) { if (!hist_trigger_match(data, iter, named_data, false)) <- never matches continue; [..] test =
iter; } if (test && test->ops->free) <<<-- test is NULL test->ops->free(test) [event_hist_trigger_free()]
{ [..] if (data->name) del_named_trigger(data) { list_del(&data->named_list); <<<<-- NEVER gets removed! }
} } } [..] kfree(data); <<<-- frees item but it is still on list The next time a hist with name is
registered, it causes an u-a-f bug and the kernel can crash. Move the code around such that if
event_trigger_register() succeeds, the next thing called is hist_trigger_enable() which adds it to the
list. A bunch of actions is called if get_named_trigger_data() returns false. But that doesn't need to be
called after event_trigger_register(), so it can be moved up, allowing event_trigger_register() to be
called just before hist_trigger_enable() keeping them together and allowing the file->triggers to be
properly populated. (CVE-2025-21899)

Solution

Update the linux library and its related packages to version 6.1.133-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-21899

Plugin Details

Severity: Medium

ID: 461936

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 96.84

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-21899

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 3/14/2025

Reference Information

CVE: CVE-2025-21899