rust-lang / docker-rust

The official Docker images for Rust
438 stars 88 forks source link

docker-rust image in dockerhub (1.64.0-slim-bullseye) has 2 Critical Vulnerabilities #117

Open izorster opened 1 year ago

izorster commented 1 year ago

│ libarchive13 │ CVE-2022-26280 │ CRITICAL │ 3.4.3-2+deb11u1 │ │ libarchive: an out-of-bounds read via the component │ │ │ │ │ │ │ zipx_lzma_alone_init │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-26280

───────────────────────────────────────────────┤ │ libdb5.3 │ CVE-2019-8457 │ CRITICAL │ 5.3.28+dfsg1-0.8 │ │ sqlite: heap out-of-bound read in function rtreenode() │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2019-8457

sfackler commented 1 year ago

It's up to docker-hub to rebuild the image.