Chainguard: linux-qemu-melange: security update to 6.18.49-r2

medium Tenable Cloud Security Plugin ID 472543

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfs: Fix zeropoint update where
i_size > remote_i_size Fix the update of the zero point[*] by netfs_release_folio() when there is
uncommitted data in the pagecache beyond the folio being released but the on-server EOF is in this folio
(ie. i_size > remote_i_size). The update needs to limit zero_point to remote_i_size, not i_size as i_size
is a local phenomenon reflecting updates made locally to the pagecache, not stuff written to the server.
remote_i_size tracks the server's i_size. [*] The zero point is the file position from which we can assume
that the server will just return zeros, so we can avoid generating reads. Note that
netfs_invalidate_folio() probably doesn't need fixing as zero_point should be updated by setattr after
truncation or fallocate. Found with: fsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \ /xfstest.test/junk
--replay-ops=junk.fsxops using the following as junk.fsxops: truncate 0x0 0x1bbae 0x82864 write 0x3ef2e
0xf9c8 0x1bbae write 0x67e05 0xcb5a 0x4e8f6 mapread 0x57781 0x85b6 0x7495f copy_range 0x5d3d 0x10329
0x54fac 0x7495f write 0x64710 0x1c2b 0x7495f mapread 0x64000 0x1000 0x7495f on cifs with the default cache
option. It shows read-gaps on folio 0x64 failing with a short read (ie. it hits EOF) if the FMODE_READ
check is commented out in netfs_perform_write(): if (//(file->f_mode & FMODE_READ) ||
netfs_is_cache_enabled(ctx)) { and no fscache. This was initially found with the generic/522 xfstest.
(CVE-2026-64159)

Solution

Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.

Plugin Details

Severity: Medium

ID: 472543

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-64159

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/19/2026

Reference Information

CVE: CVE-2026-64159