Echo: linux: security update to 6.1.170-1

medium Tenable Self-Hosted Container Security Plugin ID 463351

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix NULL pointer
dereference during unbind race Commit b81ac4395bbe ("usb: gadget: uvc: allow for application to cleanly
shutdown") introduced two stages of synchronization waits totaling 1500ms in uvc_function_unbind() to
prevent several types of kernel panics. However, this timing-based approach is insufficient during power
management (PM) transitions. When the PM subsystem starts freezing user space processes, the
wait_event_interruptible_timeout() is aborted early, which allows the unbind thread to proceed and nullify
the gadget pointer (cdev->gadget = NULL): [ 814.123447][ T947] configfs-gadget.g1 gadget.0: uvc:
uvc_function_unbind() [ 814.178583][ T3173] PM: suspend entry (deep) [ 814.192487][ T3173] Freezing user
space processes [ 814.197668][ T947] configfs-gadget.g1 gadget.0: uvc: uvc_function_unbind no clean
disconnect, wait for release When the PM subsystem resumes or aborts the suspend and tasks are restarted,
the V4L2 release path is executed and attempts to access the already nullified gadget pointer, triggering
a kernel panic: [ 814.292597][ C0] PM: pm_system_irq_wakeup: 479 triggered dhdpcie_host_wake [
814.386727][ T3173] Restarting tasks ... [ 814.403522][ T4558] Unable to handle kernel NULL pointer
dereference at virtual address 0000000000000030 [ 814.404021][ T4558] pc : usb_gadget_deactivate+0x14/0xf4
[ 814.404031][ T4558] lr : usb_function_deactivate+0x54/0x94 [ 814.404078][ T4558] Call trace: [
814.404080][ T4558] usb_gadget_deactivate+0x14/0xf4 [ 814.404083][ T4558]
usb_function_deactivate+0x54/0x94 [ 814.404087][ T4558] uvc_function_disconnect+0x1c/0x5c [ 814.404092][
T4558] uvc_v4l2_release+0x44/0xac [ 814.404095][ T4558] v4l2_release+0xcc/0x130 Address the race condition
and NULL pointer dereference by: 1. State Synchronization (flag + mutex) Introduce a 'func_unbound' flag
in struct uvc_device. This allows uvc_function_disconnect() to safely skip accessing the nullified
cdev->gadget pointer. As suggested by Alan Stern, this flag is protected by a new mutex (uvc->lock) to
ensure proper memory ordering and prevent instruction reordering or speculative loads. This mutex is also
used to protect 'func_connected' for consistent state management. 2. Explicit Synchronization (completion)
Use a completion to synchronize uvc_function_unbind() with the uvc_vdev_release() callback. This prevents
Use-After-Free (UAF) by ensuring struct uvc_device is freed after all video device resources are released.
(CVE-2026-31726)

Solution

Update the linux library and its related packages to version 6.1.170-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-31726

Plugin Details

Severity: Medium

ID: 463351

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-31726

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/2/2026

Vulnerability Publication Date: 4/23/2026

Reference Information

CVE: CVE-2026-31726