GoogleContainerTools / distroless

🥑 Language focused docker images, minus the operating system.
Apache License 2.0
19.2k stars 1.17k forks source link

CVE-2023-24329 #1540

Closed jonathannaguin closed 1 month ago

jonathannaguin commented 9 months ago

Please describe the image you encountered this with and a link to the debian security tracker https://security-tracker.debian.org/tracker/CVE-2023-24329

The stable version for Python11 in Debian 12 is 3.11.2, although 3.11.8 is available as "unstable". I am unsure how Debian tags packages but found some old threads where seem to indicate stable will never change for that release which would leave this CVE on the Distroless images until Debian trixie comes along.

loosebazooka commented 7 months ago

Yeah that's kind of an unfortunate side effect of tracking debian. This seems like a minor update on the version number though, and maybe the fix will come?

JasperJuergensen commented 5 months ago

Apparently they backported the fix: See #1613