Echo: linux: security update to 6.12.41-1

medium Tenable Self-Hosted Container Security Plugin ID 464475

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix bug due to prealloc
collision When userspace is using AF_RXRPC to provide a server, it has to preallocate incoming calls and
assign to them call IDs that will be used to thread related recvmsg() and sendmsg() together. The
preallocated call IDs will automatically be attached to calls as they come in until the pool is empty. To
the kernel, the call IDs are just arbitrary numbers, but userspace can use the call ID to hold a pointer
to prepared structs. In any case, the user isn't permitted to create two calls with the same call ID (call
IDs become available again when the call ends) and EBADSLT should result from sendmsg() if an attempt is
made to preallocate a call with an in-use call ID. However, the cleanup in the error handling will trigger
both assertions in rxrpc_cleanup_call() because the call isn't marked complete and isn't marked as having
been released. Fix this by setting the call state in rxrpc_service_prealloc_one() and then marking it as
being released before calling the cleanup function. (CVE-2025-38544)

Solution

Update the linux library and its related packages to version 6.12.41-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-38544

Plugin Details

Severity: Medium

ID: 464475

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.15

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-38544

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 8/16/2025

Reference Information

CVE: CVE-2025-38544