Echo: linux: security update to 6.3.7-1

medium Tenable Self-Hosted Container Security Plugin ID 463605

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: postpone mem_mgr IDR
destruction to hpriv_release() The memory manager IDR is currently destroyed when user releases the file
descriptor. However, at this point the user context might be still held, and memory buffers might be still
in use. Later on, calls to release those buffers will fail due to not finding their handles in the IDR,
leading to a memory leak. To avoid this leak, split the IDR destruction from the memory manager fini, and
postpone it to hpriv_release() when there is no user context and no buffers are used. (CVE-2023-53353)

Solution

Update the linux library and its related packages to version 6.3.7-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2023-53353

Plugin Details

Severity: Medium

ID: 463605

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.32

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2023-53353

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/18/2025

Vulnerability Publication Date: 9/17/2025

Reference Information

CVE: CVE-2023-53353