Echo: linux: security update to 6.1.133-1

medium Tenable Self-Hosted Container Security Plugin ID 464833

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: pci_generic: Use
pci_try_reset_function() to avoid deadlock There are multiple places from where the recovery work gets
scheduled asynchronously. Also, there are multiple places where the caller waits synchronously for the
recovery to be completed. One such place is during the PM shutdown() callback. If the device is not alive
during recovery_work, it will try to reset the device using pci_reset_function(). This function internally
will take the device_lock() first before resetting the device. By this time, if the lock has already been
acquired, then recovery_work will get stalled while waiting for the lock. And if the lock was already
acquired by the caller which waits for the recovery_work to be completed, it will lead to deadlock. This
is what happened on the X1E80100 CRD device when the device died before shutdown() callback. Driver core
calls the driver's shutdown() callback while holding the device_lock() leading to deadlock. And this
deadlock scenario can occur on other paths as well, like during the PM suspend() callback, where the
driver core would hold the device_lock() before calling driver's suspend() callback. And if the
recovery_work was already started, it could lead to deadlock. This is also observed on the X1E80100 CRD.
So to fix both issues, use pci_try_reset_function() in recovery_work. This function first checks for the
availability of the device_lock() before trying to reset the device. If the lock is available, it will
acquire it and reset the device. Otherwise, it will return -EAGAIN. If that happens, recovery_work will
fail with the error message "Recovery failed" as not much could be done. (CVE-2025-21951)

Solution

Update the linux library and its related packages to version 6.1.133-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-21951

Plugin Details

Severity: Medium

ID: 464833

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-21951

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 4/1/2025

Reference Information

CVE: CVE-2025-21951