Chainguard: multiple linux-gcp-6.18-bootc packages: security update to 6.18.38-r2

medium Tenable Cloud Security Plugin ID 473069

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: power: supply: max77705: Free
allocated workqueue and fix removal order Use devm interface for allocating workqueue to fix two bugs at
the same time: 1. Driver leaks the memory on remove(), because the workqueue is not destroyed. 2. Driver
allocates workqueue and then registers interrupt handlers with devm interface. This means that probe error
paths will not use a reversed order, but first destroy the workqueue and then, via devm release handlers,
free the interrupt. The interrupt handler schedules work on this exact workqueue, thus if interrupt is hit
in this short time window - after destroying workqueue, but before devm() frees the interrupt - the
schedulled work will lead to use of freed memory. Change is not equivalent in the workqueue itself: use
non-legacy API which does not set (__WQ_LEGACY | WQ_MEM_RECLAIM). The workqueue is used to update power
supply (power_supply_changed()) status, thus there is no point to run it for memory reclaim. Note that
dev_name() is not directly used in second argument to prevent possible unlikely parsing any "%" character
in device name as format. (CVE-2026-53308)

Solution

Update the linux-gcp-6.18-bootc library and its related packages to version 6.18.38-r2 or later.

Plugin Details

Severity: Medium

ID: 473069

Version: Revision 1.1

Type: Local

Published: 10/6/2026

Updated: 10/6/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.14

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-53308

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/26/2026

Reference Information

CVE: CVE-2026-53308