-
Notifications
You must be signed in to change notification settings - Fork 598
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
musl vulnerability in alpine #186
Comments
See docker-library/postgres#286 (comment) docker-library/openjdk#161, docker-library/openjdk#112, docker-library/postgres#286, docker-library/drupal#84, docker-library/official-images#2740, docker-library/ruby#117, docker-library/ruby#94, docker-library/python#152, docker-library/php#242, docker-library/buildpack-deps#46, docker-library/openjdk#185. A CVE doesn't imply having an actual vulnerability, and often is even a false positive (given how most distributions handle versioning/security updates in stable releases). If there are actionable items we can resolve, we're happy to do so (and do so actively). We update all Debian based images to include any updates in apt packages at least monthly (we regenerate the base images and then rebuild all dependent images). Looks like this hasn't been patched yet so there's nothing actionable we can do. As we'll only apply out-of-branch patch's when absolutely necessary
|
A couple other links: upstream tracker here; the fix was already deployed to the |
Closing in favor of alpinelinux/docker-alpine#34. |
Hi, our vulnerability scanning tool detected a version of musl that's affected by CVE-2019-14697 in docker:18.09.8-dind. It appears that a fix is available through
apk upgrade
.The text was updated successfully, but these errors were encountered: