Echo: linux: security update to 6.9.10-1

high Tenable Self-Hosted Container Security Plugin ID 462765

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Defer work in
bpf_timer_cancel_and_free Currently, the same case as previous patch (two timer callbacks trying to cancel
each other) can be invoked through bpf_map_update_elem as well, or more precisely, freeing map elements
containing timers. Since this relies on hrtimer_cancel as well, it is prone to the same deadlock situation
as the previous patch. It would be sufficient to use hrtimer_try_to_cancel to fix this problem, as the
timer cannot be enqueued after async_cancel_and_free. Once async_cancel_and_free has been done, the timer
must be reinitialized before it can be armed again. The callback running in parallel trying to arm the
timer will fail, and freeing bpf_hrtimer without waiting is sufficient (given kfree_rcu), and bpf_timer_cb
will return HRTIMER_NORESTART, preventing the timer from being rearmed again. However, there exists a UAF
scenario where the callback arms the timer before entering this function, such that if cancellation fails
(due to timer callback invoking this routine, or the target timer callback running concurrently). In such
a case, if the timer expiration is significantly far in the future, the RCU grace period expiration
happening before it will free the bpf_hrtimer state and along with it the struct hrtimer, that is
enqueued. Hence, it is clear cancellation needs to occur after async_cancel_and_free, and yet it cannot be
done inline due to deadlock issues. We thus modify bpf_timer_cancel_and_free to defer work to the global
workqueue, adding a work_struct alongside rcu_head (both used at _different_ points of time, so can share
space). Update existing code comments to reflect the new state of affairs. (CVE-2024-41045)

Solution

Update the linux library and its related packages to version 6.9.10-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-41045

Plugin Details

Severity: High

ID: 462765

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-41045

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 7/29/2024

Reference Information

CVE: CVE-2024-41045