Description
There are packages installed that are affected by a vulnerability referenced in the following CVE:
- In the Linux kernel, the following vulnerability has been resolved: udf: fix partition descriptor append
bookkeeping Mounting a crafted UDF image with repeated partition descriptors can trigger a heap out-of-
bounds write in part_descs_loc[]. handle_partition_descriptor() deduplicates entries by partition number,
but appended slots never record partnum. As a result duplicate Partition Descriptors are appended
repeatedly and num_part_descs keeps growing. Once the table is full, the growth path still sizes the
allocation from partnum even though inserts are indexed by num_part_descs. If partnum is already aligned
to PART_DESC_ALLOC_STEP, ALIGN(partnum, step) can keep the old capacity and the next append writes past
the end of the table. Store partnum in the appended slot and size growth from the next append count so
deduplication and capacity tracking follow the same model. (CVE-2026-45991)
Solution
Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.
Plugin Details
Risk Information
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 5/26/2026