Echo: linux: security update to 6.1.148-1

medium Tenable Self-Hosted Container Security Plugin ID 462262

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Fix surprise plug
detection and recovery The existing PowerNV hotplug code did not handle surprise plug events correctly,
leading to a complete failure of the hotplug system after device removal and a required reboot to detect
new devices. This comes down to two issues: 1) When a device is surprise removed, often the bridge
upstream port will cause a PE freeze on the PHB. If this freeze is not cleared, the MSI interrupts from
the bridge hotplug notification logic will not be received by the kernel, stalling all plug events on all
slots associated with the PE. 2) When a device is removed from a slot, regardless of surprise or
programmatic removal, the associated PHB/PE ls left frozen. If this freeze is not cleared via a
fundamental reset, skiboot is unable to clear the freeze and cannot retrain / rescan the slot. This also
requires a reboot to clear the freeze and redetect the device in the slot. Issue the appropriate unfreeze
and rescan commands on hotplug events, and don't oops on hotplug if pci_bus_to_OF_node() returns NULL.
[bhelgaas: tidy comments] (CVE-2025-38623)

Solution

Update the linux library and its related packages to version 6.1.148-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-38623

Plugin Details

Severity: Medium

ID: 462262

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.36

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-38623

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 8/22/2025

Reference Information

CVE: CVE-2025-38623