Echo: linux: security update to 6.1.153-1

high Tenable Self-Hosted Container Security Plugin ID 463498

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in
cpu_switch_to(), call_on_irq_stack() `cpu_switch_to()` and `call_on_irq_stack()` manipulate SP to change
to different stacks along with the Shadow Call Stack if it is enabled. Those two stack changes cannot be
done atomically and both functions can be interrupted by SErrors or Debug Exceptions which, though
unlikely, is very much broken : if interrupted, we can end up with mismatched stacks and Shadow Call Stack
leading to clobbered stacks. In `cpu_switch_to()`, it can happen when SP_EL0 points to the new task, but
x18 stills points to the old task's SCS. When the interrupt handler tries to save the task's SCS pointer,
it will save the old task SCS pointer (x18) into the new task struct (pointed to by SP_EL0), clobbering
it. In `call_on_irq_stack()`, it can happen when switching from the task stack to the IRQ stack and when
switching back. In both cases, we can be interrupted when the SCS pointer points to the IRQ SCS, but SP
points to the task stack. The nested interrupt handler pushes its return addresses on the IRQ SCS. It then
detects that SP points to the task stack, calls `call_on_irq_stack()` and clobbers the task SCS pointer
with the IRQ SCS pointer, which it will also use ! This leads to tasks returning to addresses on the wrong
SCS, or even on the IRQ SCS, triggering kernel panics via CONFIG_VMAP_STACK or FPAC if enabled. This is
possible on a default config, but unlikely. However, when enabling CONFIG_ARM64_PSEUDO_NMI, DAIF is
unmasked and instead the GIC is responsible for filtering what interrupts the CPU should receive based on
priority. Given the goal of emulating NMIs, pseudo-NMIs can be received by the CPU even in
`cpu_switch_to()` and `call_on_irq_stack()`, possibly *very* frequently depending on the system
configuration and workload, leading to unpredictable kernel panics. Completely mask DAIF in
`cpu_switch_to()` and restore it when returning. Do the same in `call_on_irq_stack()`, but restore and
mask around the branch. Mask DAIF even if CONFIG_SHADOW_CALL_STACK is not enabled for consistency of
behaviour between all configurations. Introduce and use an assembly macro for saving and masking DAIF, as
the existing one saves but only masks IF. (CVE-2025-38670)

Solution

Update the linux library and its related packages to version 6.1.153-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-38670

Plugin Details

Severity: High

ID: 463498

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.81

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2025-38670

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 4/1/2024

Reference Information

CVE: CVE-2025-38670