Echo: linux: security update to 6.1.133-1

high Tenable Self-Hosted Container Security Plugin ID 463290

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet
when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will
drop a packet in scheduler's queue and decrease scheduler's qlen by one. Then, pfifo_tail_enqueue()
enqueue new packet and increase scheduler's qlen by one. Finally, pfifo_tail_enqueue() return
`NET_XMIT_CN` status code. Weird behaviour: In case we set `sch->limit == 0` and trigger
pfifo_tail_enqueue() on a scheduler that has no packet, the 'drop a packet' step will do nothing. This
means the scheduler's qlen still has value equal 0. Then, we continue to enqueue new packet and increase
scheduler's qlen by one. In summary, we can leverage pfifo_tail_enqueue() to increase qlen by one and
return `NET_XMIT_CN` status code. The problem is: Let's say we have two qdiscs: Qdisc_A and Qdisc_B. -
Qdisc_A's type must have '->graft()' function to create parent/child relationship. Let's say Qdisc_A's
type is `hfsc`. Enqueue packet to this qdisc will trigger `hfsc_enqueue`. - Qdisc_B's type is
pfifo_head_drop. Enqueue packet to this qdisc will trigger `pfifo_tail_enqueue`. - Qdisc_B is configured
to have `sch->limit == 0`. - Qdisc_A is configured to route the enqueued's packet to Qdisc_B. Enqueue
packet through Qdisc_A will lead to: - hfsc_enqueue(Qdisc_A) -> pfifo_tail_enqueue(Qdisc_B) -
Qdisc_B->q.qlen += 1 - pfifo_tail_enqueue() return `NET_XMIT_CN` - hfsc_enqueue() check for
`NET_XMIT_SUCCESS` and see `NET_XMIT_CN` => hfsc_enqueue() don't increase qlen of Qdisc_A. The whole
process lead to a situation where Qdisc_A->q.qlen == 0 and Qdisc_B->q.qlen == 1. Replace 'hfsc' with other
type (for example: 'drr') still lead to the same problem. This violate the design where parent's qlen
should equal to the sum of its childrens'qlen. Bug impact: This issue can be used for user->kernel
privilege escalation when it is reachable. (CVE-2025-21702)

Solution

Update the linux library and its related packages to version 6.1.133-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-21702

Plugin Details

Severity: High

ID: 463290

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.5

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.4

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-21702

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 2/18/2025

Reference Information

CVE: CVE-2025-21702