Description
There are packages installed that are affected by a vulnerability referenced in the following CVE:
- In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when
accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests is
accessed without locks by netfs_collect_read_results() and netfs_collect_write_results(), and then they
access subreq->flags without taking a barrier after getting the subreq pointer from the list. Relatedly,
the functions that build the list don't use any sort of write barrier when constructing the list to make
sure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if no lock is taken. Fix this by:
(1) Add a new list_add_tail_release() function that uses a release barrier to set the pointer to the new
member of the list. (2) Add a new list_first_entry_or_null_acquire() function that uses an acquire barrier
to read the pointer to the first member in a list (or return NULL). (3) Use list_add_tail_release() when
adding a subreq to ->subrequests. (4) Use list_first_entry_or_null_acquire() when initially accessing the
front of the list (when an item is removed, the pointer to the new front iterm is obtained under the same
lock). (CVE-2026-64067)
Solution
Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.
Plugin Details
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 7/19/2026