Chainguard: linux-qemu-melange: security update to 6.18.49-r2

medium Tenable Cloud Security Plugin ID 472560

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix SCX_KICK_WAIT deadlock
by deferring wait to balance callback SCX_KICK_WAIT busy-waits in kick_cpus_irq_workfn() using
smp_cond_load_acquire() until the target CPU's kick_sync advances. Because the irq_work runs in hardirq
context, the waiting CPU cannot reschedule and its own kick_sync never advances. If multiple CPUs form a
wait cycle, all CPUs deadlock. Replace the busy-wait in kick_cpus_irq_workfn() with resched_curr() to
force the CPU through do_pick_task_scx(), which queues a balance callback to perform the wait. The balance
callback drops the rq lock and enables IRQs following the sched_core_balance() pattern, so the CPU can
process IPIs while waiting. The local CPU's kick_sync is advanced on entry to do_pick_task_scx() and
continuously during the wait, ensuring any CPU that starts waiting for us sees the advancement and cannot
form cyclic dependencies. (CVE-2026-43326)

Solution

Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.

Plugin Details

Severity: Medium

ID: 472560

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.68

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-43326

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/8/2026

Reference Information

CVE: CVE-2026-43326