Echo: linux: security update to 6.1.176-1

medium Tenable Self-Hosted Container Security Plugin ID 463911

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate minimum
block_len in ncm_unwrap_ntb() The block_len read from the host-supplied NTB header is checked against
ntb_max but has no lower bound. When block_len is smaller than opts->ndp_size, the bounds check of:
ndp_index > (block_len - opts->ndp_size) will underflow producing a huge unsigned value that ndp_index can
never exceed, defeating the check entirely. The same underflow occurs in the datagram index checks against
block_len - opts->dpe_size. With those checks neutered, a malicious USB host can choose ndp_index and
datagram offsets that point past the actual transfer, and the skb_put_data() copies adjacent kernel memory
into the network skb. Fix this by rejecting block lengths that cannot hold at least the NTB header plus
one NDP. This will make block_len - opts->ndp_size and block_len - opts->dpe_size both well-defined.
Commit 8d2b1a1ec9f5 ("CDC-NCM: avoid overflow in sanity checking") fixed a related class of issues on the
host side of NCM. (CVE-2026-31617)

Solution

Update the linux library and its related packages to version 6.1.176-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-31617

Plugin Details

Severity: Medium

ID: 463911

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-31617

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 4/24/2026

Reference Information

CVE: CVE-2026-31617