Echo: linux: security update to 6.1.133-1

medium Tenable Self-Hosted Container Security Plugin ID 463924

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: switchdev: Convert blocking
notification chain to a raw one A blocking notification chain uses a read-write semaphore to protect the
integrity of the chain. The semaphore is acquired for writing when adding / removing notifiers to / from
the chain and acquired for reading when traversing the chain and informing notifiers about an event. In
case of the blocking switchdev notification chain, recursive notifications are possible which leads to the
semaphore being acquired twice for reading and to lockdep warnings being generated [1]. Specifically, this
can happen when the bridge driver processes a SWITCHDEV_BRPORT_UNOFFLOADED event which causes it to emit
notifications about deferred events when calling switchdev_deferred_process(). Fix this by converting the
notification chain to a raw notification chain in a similar fashion to the netdev notification chain.
Protect the chain using the RTNL mutex by acquiring it when modifying the chain. Events are always
informed under the RTNL mutex, but add an assertion in call_switchdev_blocking_notifiers() to make sure
this is not violated in the future. Maintain the "blocking" prefix as events are always emitted from
process context and listeners are allowed to block. [1]: WARNING: possible recursive locking detected
6.14.0-rc4-custom-g079270089484 #1 Not tainted -------------------------------------------- ip/52731 is
trying to acquire lock: ffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at:
blocking_notifier_call_chain+0x58/0xa0 but task is already holding lock: ffffffff850918d8
((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0 other
info that might help us debug this: Possible unsafe locking scenario: CPU0 ----
lock((switchdev_blocking_notif_chain).rwsem); lock((switchdev_blocking_notif_chain).rwsem); *** DEADLOCK
*** May be due to missing lock nesting notation 3 locks held by ip/52731: #0: ffffffff84f795b0
(rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x727/0x1dc0 #1: ffffffff8731f628
(&net->rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x790/0x1dc0 #2: ffffffff850918d8
((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0 stack
backtrace: ... ? __pfx_down_read+0x10/0x10 ? __pfx_mark_lock+0x10/0x10 ?
__pfx_switchdev_port_attr_set_deferred+0x10/0x10 blocking_notifier_call_chain+0x58/0xa0
switchdev_port_attr_notify.constprop.0+0xb3/0x1b0 ? __pfx_switchdev_port_attr_notify.constprop.0+0x10/0x10
? mark_held_locks+0x94/0xe0 ? switchdev_deferred_process+0x11a/0x340
switchdev_port_attr_set_deferred+0x27/0xd0 switchdev_deferred_process+0x164/0x340
br_switchdev_port_unoffload+0xc8/0x100 [bridge] br_switchdev_blocking_event+0x29f/0x580 [bridge]
notifier_call_chain+0xa2/0x440 blocking_notifier_call_chain+0x6e/0xa0
switchdev_bridge_port_unoffload+0xde/0x1a0 ... (CVE-2025-21986)

Solution

Update the linux library and its related packages to version 6.1.133-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-21986

Plugin Details

Severity: Medium

ID: 463924

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.19

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-21986

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 4/1/2025

Reference Information

CVE: CVE-2025-21986