This is the result of bug #159556 at the gentoo bugzilla:
https://bugs.gentoo.org/show_bug.cgi?id=159556
In short, there's still a chance you leak the file descriptor, resulting in a possible vulnerability to symlink attacks.
The above link includes a patch against latest partimage which fixes the issue. Please apply it.
I'm also attaching the relevant patch.
mkstemp usage patch