-
Notifications
You must be signed in to change notification settings - Fork 4.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Multiple vulnerabilties in glibc Docker containers #29688
Comments
cc @javabypatel |
Update: Seems unrelated, created a new issue #29902
envoy/source/common/network/utility.cc Line 117 in 83e604a
|
incoming issue here GoogleContainerTools/distroless#1420 which is resolved by GoogleContainerTools/distroless#1419 will update the containers when they release (i would expect today) |
i have updated the distroless base to latest and have pending backports for it - but just saw ... |
I think this is actually fine. The latest distroless/base should not have the high critical cve on libc6. FYI though, we have |
It would be good to bump to this newer Debian 12 version 👍 |
my thought had been to wait until this batch of releases is out of the way, altho tbh i dont see any reason we cant upgrade now |
PR is here #30029 |
looks like we've released new versions. wonder why the CVEs were not mentioned in the release notes. |
they were alluded to - as these were upstream vulns i thought it less important to list out any issues that were resolved
https://www.envoyproxy.io/docs/envoy/latest/version_history/v1.27/v1.27.1 and on the release pages altho just spotted this is missing from the (pending) current changelog |
|
ah we're still on 1.26. didn't see it on https://www.envoyproxy.io/docs/envoy/latest/version_history/v1.26/v1.26.5. thanks @phlax |
i think it got missed on that branch - trying to improve these workflows atm |
(just to clarify - just the changelog was missed) |
@javabypatel you can see the current versions that are being used by checking the pins in the Dockerfilie - eg on https://github.com/envoyproxy/envoy/blob/main/ci/Dockerfile-envoy i try to keep these in sync across all branches in terms of outstanding CVEs these are generally the latest available upstream so incorporate anything currently actionable |
This issue has been automatically marked as stale because it has not had activity in the last 30 days. It will be closed in the next 7 days unless it is tagged "help wanted" or "no stalebot" or other activity occurs. Thank you for your contributions. |
This issue has been automatically closed because it has not had activity in the last 37 days. If this issue is still valid, please ping a maintainer and ask them to label it as "help wanted" or "no stalebot". Thank you for your contributions. |
There are 3 recent CVEs that appear to affect the glibc version in our Docker containers
I confirmed that our current distroless containers are vulnerable - its likely the case also with the Ubuntu containers (will confirm)
debian/ubuntu refs:
4527 appears to be medium severity and is yet to be confirmed
4813 has fixes for distroless at least - which is already on
main
- i have raised/updated backports for other branchesif the fix is there for ubuntu that will automatically get updated on next release/s
The text was updated successfully, but these errors were encountered: