Echo: linux: security update to 6.12.63-1

high Tenable Self-Hosted Container Security Plugin ID 465306

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: cifs: fix memory leak in
smb3_fs_context_parse_param error path Add proper cleanup of ctx->source and fc->source to the
cifs_parse_mount_err error handler. This ensures that memory allocated for the source strings is correctly
freed on all error paths, matching the cleanup already performed in the success path by
smb3_cleanup_fs_context_contents(). Pointers are also set to NULL after freeing to prevent potential
double-free issues. This change fixes a memory leak originally detected by syzbot. The leak occurred when
processing Opt_source mount options if an error happened after ctx->source and fc->source were
successfully allocated but before the function completed. The specific leak sequence was: 1. ctx->source =
smb3_fs_context_fullpath(ctx, '/') allocates memory 2. fc->source = kstrdup(ctx->source, GFP_KERNEL)
allocates more memory 3. A subsequent error jumps to cifs_parse_mount_err 4. The old error handler freed
passwords but not the source strings, causing the memory to leak. This issue was not addressed by commit
e8c73eb7db0a ("cifs: client: fix memory leak in smb3_fs_context_parse_param"), which only fixed leaks from
repeated fsconfig() calls but not this error path. Patch updated with minor change suggested by kernel
test robot (CVE-2025-68219)

Solution

Update the linux library and its related packages to version 6.12.63-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-68219

Plugin Details

Severity: High

ID: 465306

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.77

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68219

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/17/2025

Vulnerability Publication Date: 12/16/2025

Reference Information

CVE: CVE-2025-68219