Echo: linux: security update to 6.1.147-1

high Tenable Self-Hosted Container Security Plugin ID 463625

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Fix unbalanced
regulator disable in UTMI PHY mode When transitioning from USB_ROLE_DEVICE to USB_ROLE_NONE, the code
assumed that the regulator should be disabled. However, if the regulator is marked as always-on,
regulator_is_enabled() continues to return true, leading to an incorrect attempt to disable a regulator
which is not enabled. This can result in warnings such as: [ 250.155624] WARNING: CPU: 1 PID: 7326 at
drivers/regulator/core.c:3004 _regulator_disable+0xe4/0x1a0 [ 250.155652] unbalanced disables for
VIN_SYS_5V0 To fix this, we move the regulator control logic into tegra186_xusb_padctl_id_override()
function since it's directly related to the ID override state. The regulator is now only disabled when the
role transitions from USB_ROLE_HOST to USB_ROLE_NONE, by checking the VBUS_ID register. This ensures that
regulator enable/disable operations are properly balanced and only occur when actually transitioning
to/from host mode. (CVE-2025-38535)

Solution

Update the linux library and its related packages to version 6.1.147-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-38535

Plugin Details

Severity: High

ID: 463625

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.46

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-38535

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 8/5/2025

Reference Information

CVE: CVE-2025-38535