Echo: linux: security update to 6.1.187-1

high Tenable Self-Hosted Container Security Plugin ID 464730

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF
in create_big_sync Add hci_conn_valid() check in create_big_sync() to detect stale connections before
proceeding with BIG creation. Handle the resulting -ECANCELED in create_big_complete() and re-validate the
connection under hci_dev_lock() before dereferencing, matching the pattern used by
create_le_conn_complete() and create_pa_complete(). Keep the hci_conn object alive across the async
boundary by taking a reference via hci_conn_get() when queueing create_big_sync(), and dropping it in the
completion callback. The refcount and the lock are complementary: the refcount keeps the object allocated,
while hci_dev_lock() serializes hci_conn_hash_del()'s list_del_rcu() on hdev->conn_hash, as required by
hci_conn_del(). hci_conn_put() is called outside hci_dev_unlock() so the final put (which resolves to
kfree() via bt_link_release) does not run under hdev->lock, though the release path would be safe either
way. Without this, create_big_complete() would unconditionally dereference the conn pointer on error,
causing a use-after-free via hci_connect_cfm() and hci_conn_del(). (CVE-2026-46111)

Solution

Update the linux library and its related packages to version 6.1.187-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-46111

Plugin Details

Severity: High

ID: 464730

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-46111

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/28/2026

Reference Information

CVE: CVE-2026-46111