Echo: linux: security update to 6.1.153-1

high Tenable Self-Hosted Container Security Plugin ID 463157

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Detect events pointing
to unexpected TREs When a remote device sends a completion event to the host, it contains a pointer to the
consumed TRE. The host uses this pointer to process all of the TREs between it and the host's local copy
of the ring's read pointer. This works when processing completion for chained transactions, but can lead
to nasty results if the device sends an event for a single-element transaction with a read pointer that is
multiple elements ahead of the host's read pointer. For instance, if the host accesses an event ring while
the device is updating it, the pointer inside of the event might still point to an old TRE. If the host
uses the channel's xfer_cb() to directly free the buffer pointed to by the TRE, the buffer will be double-
freed. This behavior was observed on an ep that used upstream EP stack without 'commit 6f18d174b73d ("bus:
mhi: ep: Update read pointer only after buffer is written")'. Where the device updated the events ring
pointer before updating the event contents, so it left a window where the host was able to access the
stale data the event pointed to, before the device had the chance to update them. The usual pattern was
that the host received an event pointing to a TRE that is not immediately after the last processed one, so
it got treated as if it was a chained transaction, processing all of the TREs in between the two read
pointers. This commit aims to harden the host by ensuring transactions where the event points to a TRE
that isn't local_rp + 1 are chained. [mani: added stable tag and reworded commit message] (CVE-2025-39790)

Solution

Update the linux library and its related packages to version 6.1.153-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-39790

Plugin Details

Severity: High

ID: 463157

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.48

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-39790

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 9/11/2025

Reference Information

CVE: CVE-2025-39790