Echo: linux: security update to 6.12.88-1

high Tenable Self-Hosted Container Security Plugin ID 464184

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF
during format-change stop loopback_check_format() may stop the capture side when playback starts with
parameters that no longer match a running capture stream. Commit 826af7fa62e3 ("ALSA: aloop: Fix racy
access at PCM trigger") moved the peer lookup under cable->lock, but the actual snd_pcm_stop() still runs
after dropping that lock. A concurrent close can clear the capture entry from cable->streams[] and detach
or free its runtime while the playback trigger path still holds a stale peer substream pointer. Keep a
per-cable count of in-flight peer stops before dropping cable->lock, and make free_cable() wait for those
stops before detaching the runtime. This preserves the existing behavior while making the peer runtime
lifetime explicit. (CVE-2026-46090)

Solution

Update the linux library and its related packages to version 6.12.88-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-46090

Plugin Details

Severity: High

ID: 464184

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.03

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-46090

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/27/2026

Reference Information

CVE: CVE-2026-46090