Echo: linux: security update to 6.1.180-1

high Tenable Self-Hosted Container Security Plugin ID 463658

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix NHC entry use-after-free
on error path lowpan_nhc_do_uncompression() looks up an NHC descriptor while holding lowpan_nhc_lock. If
the descriptor has no uncompress callback, the error path drops the lock before printing nhc->name.
lowpan_nhc_del() removes descriptors under the same lock and then relies on synchronize_net() before the
owning module can be unloaded. That only waits for net RX RCU readers. lowpan_header_decompress() is also
exported and can be reached from callers that are not necessarily covered by the net core RX critical
section, for example the Bluetooth 6LoWPAN L2CAP receive path. This leaves a race where one task drops
lowpan_nhc_lock in the error path, another task unregisters and frees the matching descriptor after
synchronize_net() returns, and the first task then dereferences nhc->name for the warning. With the post-
unlock window widened, KASAN reports: BUG: KASAN: slab-use-after-free in
lowpan_nhc_do_uncompression+0x1f4/0x220 Read of size 8 lowpan_nhc_do_uncompression
lowpan_header_decompress Fix this by printing the warning before dropping lowpan_nhc_lock, so the
descriptor name is read while unregister is still excluded. The malformed packet is still rejected with
-ENOTSUPP. (CVE-2026-64452)

Solution

Update the linux library and its related packages to version 6.1.180-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-64452

Plugin Details

Severity: High

ID: 463658

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.27

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:A/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64452

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/26/2026

Vulnerability Publication Date: 7/23/2026

Reference Information

CVE: CVE-2026-64452