Echo: linux: security update to 6.12.63-1

high Tenable Self-Hosted Container Security Plugin ID 462736

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Correctly handle Rx
checksum offload errors The stmmac_rx function would previously set skb->ip_summed to CHECKSUM_UNNECESSARY
if hardware checksum offload (CoE) was enabled and the packet was of a known IP ethertype. However, this
logic failed to check if the hardware had actually reported a checksum error. The hardware status,
indicating a header or payload checksum failure, was being ignored at this stage. This could cause corrupt
packets to be passed up the network stack as valid. This patch corrects the logic by checking the
`csum_none` status flag, which is set when the hardware reports a checksum error. If this flag is set,
skb->ip_summed is now correctly set to CHECKSUM_NONE, ensuring the kernel's network stack will perform its
own validation and properly handle the corrupt packet. (CVE-2025-40337)

Solution

Update the linux library and its related packages to version 6.12.63-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-40337

Plugin Details

Severity: High

ID: 462736

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.86

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:P

CVSS Score Source: CVE-2025-40337

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/9/2025

Vulnerability Publication Date: 12/9/2025

Reference Information

CVE: CVE-2025-40337