Chainguard: linux-qemu-melange: security update to 6.18.49-r2

medium Tenable Cloud Security Plugin ID 472564

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ublk: reset per-IO canceled flag on
each fetch If a ublk server starts recovering devices but dies before issuing fetch commands for all IOs,
cancellation of the fetch commands that were successfully issued may never complete. This is because the
per-IO canceled flag can remain set even after the fetch for that IO has been submitted - the per-IO
canceled flags for all IOs in a queue are reset together only once all IOs for that queue have been
fetched. So if a nonempty proper subset of the IOs for a queue are fetched when the ublk server dies, the
IOs in that subset will never successfully be canceled, as their canceled flags remain set, and this
prevents ublk_cancel_cmd from actually calling io_uring_cmd_done on the commands, despite the fact that
they are outstanding. Fix this by resetting the per-IO cancel flags immediately when each IO is fetched
instead of waiting for all IOs for the queue (which may never happen). (CVE-2026-53124)

Solution

Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.

Plugin Details

Severity: Medium

ID: 472564

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-53124

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/24/2026

Reference Information

CVE: CVE-2026-53124