GoogleContainerTools / distroless

🥑 Language focused docker images, minus the operating system.
Apache License 2.0
18.17k stars 1.11k forks source link

CVE-2024-2961 #1577

Closed Manish-Ghumnani closed 2 months ago

Manish-Ghumnani commented 2 months ago

Please describe the image you encountered this with and a link to the debian security tracker https://security-tracker.debian.org/tracker/CVE-2024-2961

solotoo commented 2 months ago

Hi, is there any movement on this issue, no new image available and trivy reporting

┌─────────┬───────────────┬──────────┬───────────────────┬─────────────────┬────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Installed Version │  Fixed Version  │                         Title                          │
├─────────┼───────────────┼──────────┼───────────────────┼─────────────────┼────────────────────────────────────────────────────────┤
│ libc6   │ CVE-2024-2961 │ HIGH     │ 2.31-13+deb11u8   │ 2.31-13+deb11u9 │ glibc: Out of bounds write in iconv may lead to remote │
│         │               │          │                   │                 │ code...                                                │
│         │               │          │                   │                 │ https://avd.aquasec.com/nvd/cve-2024-2961              │
└─────────┴───────────────┴──────────┴───────────────────┴─────────────────┴────────────────────────────────────────────────────────┘
loosebazooka commented 2 months ago

This should've been picked up automatically. Lemme take a look

loosebazooka commented 2 months ago

this isn't exactly closed yet, but new images should be up in the next few hours