docker-library / buildpack-deps

MIT License
450 stars 115 forks source link

CVE-2023-52425⁠ in debian based images #156

Closed JGSweets closed 7 months ago

JGSweets commented 7 months ago

Is there any work being done to resolve CVE-2023-52425?

Debian base images do not have this issue at this time.

Thanks!

yosifkit commented 7 months ago

No fix is available for bookworm (aka stable) or bullseye (aka old-stable): https://security-tracker.debian.org/tracker/CVE-2023-52425, so there is nothing we can do aside from (the not insignificant task of) contributing the fix in Debian.