Echo: linux: security update to 6.1.170-1

high Tenable Self-Hosted Container Security Plugin ID 463205

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix use-after-free in
sock_def_readable() A race condition exists between lec_atm_close() setting priv->lecd to NULL and
concurrent access to priv->lecd in send_to_lecd(), lec_handle_bridge(), and lec_atm_send(). When the
socket is freed via RCU while another thread is still using it, a use-after-free occurs in
sock_def_readable() when accessing the socket's wait queue. The root cause is that lec_atm_close() clears
priv->lecd without any synchronization, while callers dereference priv->lecd without any protection
against concurrent teardown. Fix this by converting priv->lecd to an RCU-protected pointer: - Mark
priv->lecd as __rcu in lec.h - Use rcu_assign_pointer() in lec_atm_close() and lecd_attach() for safe
pointer assignment - Use rcu_access_pointer() for NULL checks that do not dereference the pointer in
lec_start_xmit(), lec_push(), send_to_lecd() and lecd_attach() - Use
rcu_read_lock/rcu_dereference/rcu_read_unlock in send_to_lecd(), lec_handle_bridge() and lec_atm_send() to
safely access lecd - Use rcu_assign_pointer() followed by synchronize_rcu() in lec_atm_close() to ensure
all readers have completed before proceeding. This is safe since lec_atm_close() is called from
vcc_release() which holds lock_sock(), a sleeping lock. - Remove the manual sk_receive_queue drain from
lec_atm_close() since vcc_destroy_socket() already drains it after lec_atm_close() returns. v2: Switch
from spinlock + sock_hold/put approach to RCU to properly fix the race. The v1 spinlock approach had two
issues pointed out by Eric Dumazet: 1. priv->lecd was still accessed directly after releasing the lock
instead of using a local copy. 2. The spinlock did not prevent packets being queued after lec_atm_close()
drains sk_receive_queue since timer and workqueue paths bypass netif_stop_queue(). Note: Syzbot patch
testing was attempted but the test VM terminated unexpectedly with "Connection to localhost closed by
remote host", likely due to a QEMU AHCI emulation issue unrelated to this fix. Compile testing with "make
W=1 net/atm/lec.o" passes cleanly. (CVE-2026-43050)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-43050

Plugin Details

Severity: High

ID: 463205

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.94

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.4

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-43050

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/2/2026

Vulnerability Publication Date: 4/23/2026

Reference Information

CVE: CVE-2026-43050