Description
There are packages installed that are affected by a vulnerability referenced in the following CVE:
- In the Linux kernel, the following vulnerability has been resolved: ublk: reset per-IO canceled flag on
each fetch If a ublk server starts recovering devices but dies before issuing fetch commands for all IOs,
cancellation of the fetch commands that were successfully issued may never complete. This is because the
per-IO canceled flag can remain set even after the fetch for that IO has been submitted - the per-IO
canceled flags for all IOs in a queue are reset together only once all IOs for that queue have been
fetched. So if a nonempty proper subset of the IOs for a queue are fetched when the ublk server dies, the
IOs in that subset will never successfully be canceled, as their canceled flags remain set, and this
prevents ublk_cancel_cmd from actually calling io_uring_cmd_done on the commands, despite the fact that
they are outstanding. Fix this by resetting the per-IO cancel flags immediately when each IO is fetched
instead of waiting for all IOs for the queue (which may never happen). (CVE-2026-53124)
Solution
Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.
Plugin Details
Risk Information
Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 6/24/2026