-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2024-6119 is fixed upstream but -chiseled images have not been updated #5862
Comments
Hi @skolima, please refer to the Image Update Policy for this. Currently, we only re-build images in response to base image updates and critical severity CVEs. As Chiseled is a "distroless" image, it has no base image that can be updated. NIST has no official CVSS score for CVE-2024-6119 yet, and I see a mix of medium and high scores from other reports. So we won't likely re-build images for this CVE alone. The thinking is that consumers of these images would be able to apply updates themselves if they deemed their app susceptible to a specific vulnerability. That prevents too many unnecessary downstream rebuilds. However, Ubuntu Chiseled currently provides limited support for extending or updating images. There is ongoing work on the Ubuntu side to address this (tracked here and here). We're open to feedback on whether we need to change our approach for distroless images until we have better guidance for updating packages. I suspect we haven't got too many reports of non-critical CVEs in Chiseled images because the attack surface is fundamentally so much smaller. Unrelated to all of that, you should expect images to be re-built tomorrow as part of Patch Tuesday. So be on the look out for an updated base image. |
These images have now been re-built. I checked and don't see CVE-2024-6119 after scanning |
Describe the Bug
CVE-2024-6119 is fixed upstream but
-chiseled
images have not been updated.dotnet-sdk
images (non-chiseled) have been recreated after upstream released a fix and are no longer affected. Ubuntu CVE information: https://ubuntu.com/security/CVE-2024-6119Steps to Reproduce
Trivy/Aquascanner output
Other Information
Output of
docker version
docker version
Output of
docker info
docker info
The text was updated successfully, but these errors were encountered: