Echo: linux: security update to 6.1.140-1

medium Tenable Self-Hosted Container Security Plugin ID 465863

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer
When bpf_redirect_peer is used to redirect packets to a device in another network namespace, the skb isn't
scrubbed. That can lead skb information from one namespace to be "misused" in another namespace. As one
example, this is causing Cilium to drop traffic when using bpf_redirect_peer to redirect packets that just
went through IPsec decryption to a container namespace. The following pwru trace shows (1) the packet path
from the host's XFRM layer to the container's XFRM layer where it's dropped and (2) the number of active
skb extensions at each function. NETNS MARK IFACE TUPLE FUNC 4026533547 d00 eth0
10.244.3.124:35473->10.244.2.158:53 xfrm_rcv_cb .active_extensions = (__u8)2, 4026533547 d00 eth0
10.244.3.124:35473->10.244.2.158:53 xfrm4_rcv_cb .active_extensions = (__u8)2, 4026533547 d00 eth0
10.244.3.124:35473->10.244.2.158:53 gro_cells_receive .active_extensions = (__u8)2, [...] 4026533547 0
eth0 10.244.3.124:35473->10.244.2.158:53 skb_do_redirect .active_extensions = (__u8)2, 4026534999 0 eth0
10.244.3.124:35473->10.244.2.158:53 ip_rcv .active_extensions = (__u8)2, 4026534999 0 eth0
10.244.3.124:35473->10.244.2.158:53 ip_rcv_core .active_extensions = (__u8)2, [...] 4026534999 0 eth0
10.244.3.124:35473->10.244.2.158:53 udp_queue_rcv_one_skb .active_extensions = (__u8)2, 4026534999 0 eth0
10.244.3.124:35473->10.244.2.158:53 __xfrm_policy_check .active_extensions = (__u8)2, 4026534999 0 eth0
10.244.3.124:35473->10.244.2.158:53 __xfrm_decode_session .active_extensions = (__u8)2, 4026534999 0 eth0
10.244.3.124:35473->10.244.2.158:53 security_xfrm_decode_session .active_extensions = (__u8)2, 4026534999
0 eth0 10.244.3.124:35473->10.244.2.158:53 kfree_skb_reason(SKB_DROP_REASON_XFRM_POLICY)
.active_extensions = (__u8)2, In this case, there are no XFRM policies in the container's network
namespace so the drop is unexpected. When we decrypt the IPsec packet, the XFRM state used for decryption
is set in the skb extensions. This information is preserved across the netns switch. When we reach the
XFRM policy check in the container's netns, __xfrm_policy_check drops the packet with
LINUX_MIB_XFRMINNOPOLS because a (container-side) XFRM policy can't be found that matches the (host-side)
XFRM state used for decryption. This patch fixes this by scrubbing the packet when using
bpf_redirect_peer, as is done on typical netns switches via veth devices except skb->mark and skb->tstamp
are not zeroed. (CVE-2025-37959)

Solution

Update the linux library and its related packages to version 6.1.140-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-37959

Plugin Details

Severity: Medium

ID: 465863

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-37959

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 5/20/2025

Reference Information

CVE: CVE-2025-37959