Chainguard: linux-qemu-melange: security update to 6.18.49-r2

high Tenable Cloud Security Plugin ID 472562

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: udf: fix partition descriptor append
bookkeeping Mounting a crafted UDF image with repeated partition descriptors can trigger a heap out-of-
bounds write in part_descs_loc[]. handle_partition_descriptor() deduplicates entries by partition number,
but appended slots never record partnum. As a result duplicate Partition Descriptors are appended
repeatedly and num_part_descs keeps growing. Once the table is full, the growth path still sizes the
allocation from partnum even though inserts are indexed by num_part_descs. If partnum is already aligned
to PART_DESC_ALLOC_STEP, ALIGN(partnum, step) can keep the old capacity and the next append writes past
the end of the table. Store partnum in the appended slot and size growth from the next append count so
deduplication and capacity tracking follow the same model. (CVE-2026-45991)

Solution

Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.

Plugin Details

Severity: High

ID: 472562

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.35

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-45991

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/26/2026

Reference Information

CVE: CVE-2026-45991