Echo: linux: security update to 6.12.85-1

high Tenable Self-Hosted Container Security Plugin ID 464590

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Flush MSI-X write before
unmapping its ATU entry Endpoint drivers use dw_pcie_ep_raise_msix_irq() to raise an MSI-X interrupt to
the host using a writel(), which generates a PCI posted write transaction. There's no completion for
posted writes, so the writel() may return before the PCI write completes. dw_pcie_ep_raise_msix_irq() also
unmaps the outbound ATU entry used for the PCI write, so the write races with the unmap. If the PCI write
loses the race with the ATU unmap, the write may corrupt host memory or cause IOMMU errors, e.g., these
when running fio with a larger queue depth against nvmet-pci-epf: arm-smmu-v3 fc900000.iommu:
0x0000010000000010 arm-smmu-v3 fc900000.iommu: 0x0000020000000000 arm-smmu-v3 fc900000.iommu:
0x000000090000f040 arm-smmu-v3 fc900000.iommu: 0x0000000000000000 arm-smmu-v3 fc900000.iommu: event:
F_TRANSLATION client: 0000:01:00.0 sid: 0x100 ssid: 0x0 iova: 0x90000f040 ipa: 0x0 arm-smmu-v3
fc900000.iommu: unpriv data write s1 "Input address caused fault" stag: 0x0 Flush the write by performing
a readl() of the same address to ensure that the write has reached the destination before the ATU entry is
unmapped. The same problem was solved for dw_pcie_ep_raise_msi_irq() in commit 8719c64e76bf ("PCI: dwc:
ep: Cache MSI outbound iATU mapping"), but there it was solved by dedicating an outbound iATU only for
MSI. We can't do the same for MSI-X because each vector can have a different msg_addr and the msg_addr may
be changed while the vector is masked. [bhelgaas: commit log] (CVE-2026-23361)

Solution

Update the linux library and its related packages to version 6.12.85-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-23361

Plugin Details

Severity: High

ID: 464590

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.76

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-23361

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2026

Vulnerability Publication Date: 3/25/2026

Reference Information

CVE: CVE-2026-23361