Echo: linux: security update to 6.1.147-1

high Tenable Self-Hosted Container Security Plugin ID 463151

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: Eliminate recurrent out-
of-bounds bug in usbhid_parse() Update struct hid_descriptor to better reflect the mandatory and optional
parts of the HID Descriptor as per USB HID 1.11 specification. Note: the kernel currently does not parse
any optional HID class descriptors, only the mandatory report descriptor. Update all references to member
element desc[0] to rpt_desc. Add test to verify bLength and bNumDescriptors values are valid. Replace the
for loop with direct access to the mandatory HID class descriptor member for the report descriptor. This
eliminates the possibility of getting an out-of-bounds fault. Add a warning message if the HID descriptor
contains any unsupported optional HID class descriptors. (CVE-2025-38103)

Solution

Update the linux library and its related packages to version 6.1.147-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-38103

Plugin Details

Severity: High

ID: 463151

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.47

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2025-38103

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 7/3/2025

Reference Information

CVE: CVE-2025-38103