Closed geetasg closed 3 months ago
I think these are fixed now in Master. Is there any plan to release a 0.8.18 release soon? @wangzhen127 , @Random-Liu @vteratipally
When is this needed? I see the base image was also updated. We could release a new version for the CVE fixes.
Please cut a release this week if possible. Also - we found a new CVE - CVE-2024-28085 - in our latest scan. I think it will also get addressed with the new release. Please clarify if I should report it separate from this issue. Thanks!
Will release v0.8.18 later this week.
Found two more CVEs
perl 5.36.0-7+deb12u1
NVD
CVE-2023-47100
Published: 2023-12-02 - Modified: 2023-12-14
CVSS v3: 9.8
Description
In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.
glibc 2.36-9+deb12u3
NVD
CVE-2023-6246
Published: 2024-01-31 - Modified: 2024-02-16
CVSS v3: 7.8
Description
A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer.
Please try to address them in the next release as well
As @wangzhen127 mentioned, v0.18.8 should be released this week. Current staging image should include all the latest fixes.
% trivy image --severity LOW,MEDIUM,HIGH,CRITICAL --ignore-unfixed --exit-code 3 --exit-on-eol 7 --scanners vuln gcr.io/k8s-staging-npd/node-problem-detector:master
2024-04-04T06:12:15.770+0300 INFO Vulnerability scanning is enabled
2024-04-04T06:12:24.878+0300 INFO Detected OS: debian
2024-04-04T06:12:24.878+0300 INFO Detecting Debian vulnerabilities...
2024-04-04T06:12:24.889+0300 INFO Number of language-specific files: 3
2024-04-04T06:12:24.889+0300 INFO Detecting gobinary vulnerabilities...
gcr.io/k8s-staging-npd/node-problem-detector:master (debian 12.5)
Total: 0 (LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)
v0.8.18 has released.
/close
@wangzhen127: Closing this issue.
A scan shows 6 high CVEs for version 0.8.17. This issue to request when might these get fixed.