Chainguard: linux-qemu-melange: security update to 6.18.49-r2

critical Tenable Cloud Security Plugin ID 472563

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when
accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests is
accessed without locks by netfs_collect_read_results() and netfs_collect_write_results(), and then they
access subreq->flags without taking a barrier after getting the subreq pointer from the list. Relatedly,
the functions that build the list don't use any sort of write barrier when constructing the list to make
sure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if no lock is taken. Fix this by:
(1) Add a new list_add_tail_release() function that uses a release barrier to set the pointer to the new
member of the list. (2) Add a new list_first_entry_or_null_acquire() function that uses an acquire barrier
to read the pointer to the first member in a list (or return NULL). (3) Use list_add_tail_release() when
adding a subreq to ->subrequests. (4) Use list_first_entry_or_null_acquire() when initially accessing the
front of the list (when an item is removed, the pointer to the new front iterm is obtained under the same
lock). (CVE-2026-64067)

Solution

Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.

Plugin Details

Severity: Critical

ID: 472563

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.19

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64067

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/19/2026

Reference Information

CVE: CVE-2026-64067