Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

UBI build affected by CVE-2024-2398, CVE-2024-37370, CVE-2024-37371, CVE-2021-43618 #734

Closed
IdanAdar opened this issue Aug 27, 2024 · 5 comments
Labels
kind/bug Something isn't working

Comments

@IdanAdar
Copy link
Contributor

IdanAdar commented Aug 27, 2024

The UBI build is affected by the following CVEs:
CVE-2024-2398, CVE-2024-37370, CVE-2024-37371, CVE-2021-43618

A new release is required in order for the base OS packages fixes to be pulled in.
When is the next scheduled release for Reloader?

The following PR can help handle this for future releases:
#717

@IdanAdar IdanAdar added the kind/bug Something isn't working label Aug 27, 2024
@MuneebAijaz
Copy link
Contributor

@IdanAdar waiting for someone to respond to a comment on that PR, then i can merge it.

@IdanAdar
Copy link
Contributor Author

@MuneebAijaz Jack has replied.
These CVEs have a due date of September 6th.

@IdanAdar
Copy link
Contributor Author

@MuneebAijaz if the PR can't be merged soon enough we require a release without it in the meanwhile, please.

@MuneebAijaz
Copy link
Contributor

@IdanAdar merge-735-ubi is available for use. https://github.com/stakater/Reloader/pkgs/container/reloader. I will work towards manual release soon

@MuneebAijaz
Copy link
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants