Echo: linux: security update to 6.10.9-1

medium Tenable Self-Hosted Container Security Plugin ID 464875

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable DMCUB timeout
for DCN35 [Why] DMCUB can intermittently take longer than expected to process commands. Old ASIC policy
was to continue while logging a diagnostic error - which works fine for ASIC without IPS, but with IPS
this could lead to a race condition where we attempt to access DCN state while it's inaccessible, leading
to a system hang when the NIU port is not disabled or register accesses that timeout and the display
configuration in an undefined state. [How] We need to investigate why these accesses take longer than
expected, but for now we should disable the timeout on DCN35 to avoid this race condition. Since the waits
happen only at lower interrupt levels the risk of taking too long at higher IRQ and causing a system
watchdog timeout are minimal. (CVE-2024-46870)

Solution

Update the linux library and its related packages to version 6.10.9-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-46870

Plugin Details

Severity: Medium

ID: 464875

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-46870

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 10/9/2024

Reference Information

CVE: CVE-2024-46870