GoogleContainerTools / distroless

🥑 Language focused docker images, minus the operating system.
Apache License 2.0
19.05k stars 1.17k forks source link

CVE-2023-52425 #1530

Closed jonathannaguin closed 8 months ago

jonathannaguin commented 8 months ago

Please describe the image you encountered this with and a link to the debian security tracker https://security-tracker.debian.org/tracker/CVE-2023-52425

Images affected:

Current version is on 2.5.0, fix available on 2.6.0.

loosebazooka commented 8 months ago

There is no fix available. Box 3 should not have been checked. We cannot fix this until debian releases a fix.

dlorenc commented 8 months ago

FYI - we have this fixed in the chainguard images, our expat is at 2.6.0: https://github.com/wolfi-dev/os/blob/main/expat.yaml

Feel free to try:

% grype cgr.dev/chainguard/jdk
 ✔ Vulnerability DB                [no update available]
 ✔ Loaded image                                                                                 cgr.dev/chainguard/jdk:latest
 ✔ Parsed image                                       sha256:dd715d4d9fbef5fe194eb7af70644af7655a5ea6ba54866a181c5c758e1f9345
 ✔ Cataloged packages              [68 packages]
 ✔ Scanned for vulnerabilities     [0 vulnerability matches]
   ├── by severity: 0 critical, 0 high, 0 medium, 0 low, 0 negligible
   └── by status:   0 fixed, 0 not-fixed, 0 ignored
No vulnerabilities found