Skip to content

Security triage review: 2026-07-30 (part 2/10) #131

Description

@github-actions

Automated Flatcar security-triage review batch 30521416158, part 2 of 10.

Run metadata

Summary

This part contains 31 decision group(s).

Recommendation Count
discovery_create_issue 2
discovery_ignore 27
discovery_kernel_routing 1
discovery_update_issue 1
Confidence Count
high 18
low 2
medium 11
Severity Count
CRITICAL 1
HIGH 3
n/a 27

Whole batch: 270 decision group(s) across 10 part(s).

Recommendation Count
cleanup_keep_open 16
discovery_create_issue 31
discovery_ignore 214
discovery_kernel_routing 4
discovery_update_issue 5
Confidence Count
high 169
low 34
medium 67
Severity Count
CRITICAL 4
HIGH 7
MEDIUM 3
n/a 256

How to use this review

  • Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
  • Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
  • Close this issue with reason Completed to apply every checked, conflict-free action.
  • Close this issue as Not planned (or leave it open) to take no automated action at all.
  • Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.

Decision groups

Group 21: dev-lang/go (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979580
  • CVEs / upstream IDs: CVE-2026-42505, GO ISSUE 79282
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: unknown)
  • Recommendation: update_existing_issue (confidence: medium)
  • SBOM matches: cloud.google.com/go v0.121.6 (exact_name); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (exact_name); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.7 (exact_name)
  • Existing issue matches: update: dev-lang/go #64 (open): update: dev-lang/go

Open issue #64 already tracks dev-lang/go and Gentoo bug 979580; CVE-2026-42505, its ECH privacy-leak description, affected/fixed versions (before 1.25.12/1.26.5), and references are new information not present in that issue.

Proposed additive update for action disc-490ad96b4dcc17654e1b (issue #64)

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-42505, GO ISSUE 79282
- Add Gentoo aliases/CVEs: CVE-2026-42505
- Add upstream context: Go crypto/tls Encrypted Client Hello leaked pre-shared key identities to passive network observers, potentially revealing the server hostname despite ECH.
- Review Gentoo severity: trivial (source: https://groups.google.com/g/golang-dev/c/aid3V6iXQ0Y)
- Review upstream references: https://groups.google.com/g/golang-dev/c/aid3V6iXQ0Y, http://bugs.gentoo.org/show_bug.cgi?id=979521, https://go.dev/issue/79282, https://codeberg.org/gentoo/gentoo/pulls/1510
- Review Bugzilla description: Quoting from https://groups.google.com/g/golang-dev/c/aid3V6iXQ0Y:

We have just released Go versions 1.26.5 and 1.25.12, minor point releases.

These releases include 2 security fixes following the security policy:

os: Root escape via symlink plus trailing slash

On Unix systems, op...

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=24dac47784949a95b4ad43c5c28b7dd0616fc36e

commit 24dac47784949a95b4ad43c5c28b7dd0616fc36e
Author: Holger Hoffstätte holger@applied-asynchrony.com
AuthorDate: 2026-07-23 09:10:48 +00...

New Bugzilla comments in the processing window:

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=24dac47784949a95b4ad43c5c28b7dd0616fc36e

commit 24dac47784949a95b4ad43c5c28b7dd0616fc36e
Author: Holger Hoffstätte holger@applied-asynchrony.com
AuthorDate: 2026-07-23 09:10:48 +00...

Source: https://bugs.gentoo.org/979580

This is a guarded automation recommendation; maintainers should review before editing the advisory body.


This update is re-applied against the issue's current body at apply time and never removes existing content.
</details>

Choose at most one (leave all unchecked to take no action for this group):

- [ ] Update existing issue #64 with new upstream context <!-- security-triage:action-id:disc-490ad96b4dcc17654e1b -->

### Group 22: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin (discovery, source: gentoo)

- Source URL: `https://bugs.gentoo.org/979647`
- CVEs / upstream IDs: CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057, CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147, CVE-2026-41254
- CVSS: 5.3, 5.9, 3.7, 7.5, 7.4, 6.5
- Flatcar relevance: **needs_manual_review** (scope: unknown)
- Recommendation: **needs_manual_review** (confidence: low)
- SBOM matches: none
- Existing issue matches: none

> LLM relevance decision requested manual review.

- Safety/ambiguity notes: LLM relevance decision requested manual review.

<details><summary>Exact proposed issue for action <code>disc-bd139335fe9a8f719d8a</code></summary>

Title: `update: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin`

```text
Name: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin
CVEs: CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057, CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147, CVE-2026-41254
CVSSs: 5.3, 5.9, 3.7, 7.5, 7.4, 6.5
Action Needed: TBD
Summary: OpenJDK vulnerability advisory covering multiple security issues in core, client, security, and scripting libraries; Gentoo added fixes for OpenJDK 8, 11, 17, 21, and 25, while binary and JRE binary updates were not yet available.

refmap.gentoo: https://bugs.gentoo.org/979647

Labels: advisory, security, cvss/HIGH

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 23: www-client/firefox and www-client/firefox-bin (discovery, source: gentoo)

The advisory affects Firefox desktop browser packages, which are not evidenced as shipped or used by Flatcar; no production SBOM match exists.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 24: www-client/chromium, www-client/google-chrome, www-client/microsoft-edge, www-client/opera, www-client/opera-gx, www-client/vivaldi, www-client/vivaldi-snapshot (discovery, source: gentoo)

The advisory concerns Chromium-based desktop browser packages, which are not relevant server packages for Flatcar, and there is no evidence that any affected browser is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 25: knot-resolver (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979670
  • CVEs / upstream IDs: CVE-2026-66374
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Knot Resolver is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 26: weechat (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979673
  • CVEs / upstream IDs: GHSA-68ff-gq39-pqjm
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

WeeChat is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 27: net-dns/pdns-recursor (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979682
  • CVEs / upstream IDs: CVE-2026-52688, CVE-2026-52686, CVE-2026-62686
  • CVSS: 7.5, 3.7
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: github.com/miekg/dns v1.1.61 (unique_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 28: dev-libs/aws-c-http; dev-libs/aws-c-event-stream; dev-cpp/aws-sdk-cpp (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979685
  • CVEs / upstream IDs: CVE-2026-12043, CVE-2026-5190
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: go.opentelemetry.io/auto/sdk v1.1.0 (ambiguous_substring); go.opentelemetry.io/auto/sdk v1.1.0 (ambiguous_substring); go.opentelemetry.io/auto/sdk v1.2.1 (ambiguous_substring); go.opentelemetry.io/auto/sdk v1.2.1 (ambiguous_substring); go.opentelemetry.io/auto/sdk v1.2.1 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.31.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.31.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.35.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.37.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.38.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.38.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 29: thunderbird, thunderbird-bin (discovery, source: gentoo)

This concerns Thunderbird desktop email-client packages, with no evidence that Flatcar ships or uses them.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 30: rsyslog (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979705
  • CVEs / upstream IDs: GHSA-cj5r-wh2m-7w29
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); golang.org/x/sys v0.23.0 (ambiguous_substring); golang.org/x/sys v0.29.0 (ambiguous_substring); golang.org/x/sys v0.29.0 (ambiguous_substring); golang.org/x/sys v0.29.0 (ambiguous_substring); golang.org/x/sys v0.32.0 (ambiguous_substring); golang.org/x/sys v0.32.0 (ambiguous_substring); golang.org/x/sys v0.32.0 (ambiguous_substring); golang.org/x/sys v0.37.0 (ambiguous_substring); golang.org/x/sys v0.38.0 (ambiguous_substring); golang.org/x/sys v0.38.0 (ambiguous_substring); golang.org/x/sys v0.46.0 (ambiguous_substring); golang.org/x/sys v0.46.0 (ambiguous_substring); golang.org/x/sys v0.46.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 31: dev-python/gitpython (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979713
  • CVEs / upstream IDs: GHSA-94p4-4cq8-9g67
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: dev-vcs/git 2.53.0 (unique_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 32: dev-qt/qtbase (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979715
  • CVEs / upstream IDs: CVE-2026-15037
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Qt/qtbase is a desktop-oriented graphical stack component, and the evidence provides no indication that Flatcar ships or uses it.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 33: net-libs/webkit-gtk (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979717
  • CVEs / upstream IDs: CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

WebKitGTK/WPE WebKit is a graphical web-rendering stack, which is outside Flatcar's minimal server-focused package scope, and there is no production SBOM evidence that it is shipped or used.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 34: dev-perl/YAML-Syck (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979724
  • CVEs / upstream IDs: CVE-2026-13713, CVE-2026-4177, CVE-2026-5089, CVE-2026-57075, CVE-2026-57076, CVE-2026-57077
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: sigs.k8s.io/yaml v1.4.0 (ambiguous_substring); sigs.k8s.io/yaml v1.4.0 (ambiguous_substring); sigs.k8s.io/yaml v1.4.0 (ambiguous_substring); sigs.k8s.io/yaml v1.6.0 (ambiguous_substring); sigs.k8s.io/yaml v1.6.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 35: dev-perl/XML-LibXML (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979725
  • CVEs / upstream IDs: CVE-2026-8177
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

CVE-2026-8177 affects the Perl module dev-perl/XML-LibXML, and the evidence provides no indication that this package is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 36: dev-perl/Plack (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979750
  • CVEs / upstream IDs: CVE-2025-40926
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The affected Perl package dev-perl/Plack is not present in the provided production SBOM evidence, and there is no evidence that Flatcar ships or uses Plack::Middleware::Session::Simple.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 37: www-client/chromium and related Chromium-based browser packages (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979752
  • CVEs / upstream IDs: CVE-2026-16804, CVE-2026-16805, CVE-2026-16806, CVE-2026-16807
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); sys-apps/sed 4.9-r1 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 38: dev-ruby/zlib (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979772
  • CVEs / upstream IDs: CVE-2026-27820, GHSA-g857-hhfv-j68w
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: sys-libs/zlib 1.3.2-r1 (exact_name); virtual/zlib 1.3.1-r1 (exact_name)
  • Existing issue matches: none

CVE-2026-27820 affects the Ruby dev-ruby/zlib gem, while the production SBOM only contains the distinct native sys-libs/zlib library and virtual/zlib provider; no Flatcar Ruby-gem usage is evidenced.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 39: dev-ruby/erb (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979773
  • CVEs / upstream IDs: CVE-2026-41316, GHSA-q339-8rmv-2mhv
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

This is a Ruby/ERB application-ecosystem vulnerability, and the bundle provides no evidence that Ruby or the erb gem is shipped or used by Flatcar production images.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 40: dev-ruby/net-imap (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979774
  • CVEs / upstream IDs: CVE-2026-42245, CVE-2026-42246, CVE-2026-42256, CVE-2026-42257, CVE-2026-42258, CVE-2026-47240, CVE-2026-47241, CVE-2026-47242, GHSA-46q3-7gv7-qmgg, GHSA-75xq-5h9v-w6px, GHSA-87pf-fpwv-p7m7, GHSA-8p34-64r3-mwg8, GHSA-c4fp-cxrr-mj66, GHSA-hm49-wcqc-g2xg, GHSA-q2mw-fvj9-vvcw, GHSA-vcgp-9326-pqcp
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.38.0 (ambiguous_substring); golang.org/x/net v0.39.0 (ambiguous_substring); golang.org/x/net v0.39.0 (ambiguous_substring); golang.org/x/net v0.43.0 (ambiguous_substring); golang.org/x/net v0.46.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 41: dev-lang/ruby (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979775
  • CVEs / upstream IDs: CVE-2026-46727
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Ruby is an unrelated application-language runtime for Flatcar absent evidence that it is shipped or used; no production SBOM match or existing Flatcar issue is present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 42: dev-java/openjfx (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979804
  • CVEs / upstream IDs: 979804
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory concerns the desktop JavaFX package dev-java/openjfx and its build-time bundled Gradle; no Flatcar SBOM or other evidence shows this package is shipped or used.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 43: media-radio/svxlink (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/979827
  • CVEs / upstream IDs: GHSA-pc2g-2p95-4cr5
  • CVSS: 9.8
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

svxlink is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches or existing Flatcar issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 44: dev-libs/log4cxx (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980048
  • CVEs / upstream IDs: CVE-2026-40023
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 45: dev-java/bcprov (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980052
  • CVEs / upstream IDs: CVE-2026-12185, CVE-2026-12802, CVE-2026-12803, CVE-2026-12816, CVE-2026-12817, CVE-2026-12852, CVE-2026-12860, CVE-2026-13506, CVE-2026-13586, CVE-2026-14682, CVE-2026-15505, CVE-2026-58059, CVE-2026-58060, CVE-2026-58061, CVE-2026-58062, CVE-2026-58063, CVE-2026-59638, CVE-2026-59639, CVE-2026-59640, CVE-2026-59641, CVE-2026-59642, CVE-2026-59643, CVE-2026-59644, CVE-2026-59645, CVE-2026-59646, CVE-2026-59647, CVE-2026-59648, CVE-2026-59649, CVE-2026-59650, CVE-2026-59651, CVE-2026-59652, CVE-2026-8763
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory concerns dev-java/bcprov, but the bundle provides no evidence that Bouncy Castle or a Java runtime using it is shipped or used by Flatcar, and there are no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 46: libarchive (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980054
  • CVEs / upstream IDs: 980054
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: production)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: app-arch/libarchive 3.8.7 (exact_name)
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-d5a361fc777114d333ae

Title: update: libarchive

Name: libarchive
CVEs: TBD
CVSSs: n/a
Action Needed: TBD
Summary: Gentoo tracks unspecified multiple libarchive vulnerabilities associated with the 3.8.9 security and bugfix release; specific issues and identifiers are not provided.

refmap.gentoo: https://bugs.gentoo.org/980054

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: libarchive
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 47: dev-ruby/activestorage (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980072
  • CVEs / upstream IDs: CVE-2026-66066
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: cloud.google.com/go/storage v1.57.0 (unique_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 48: gegl (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980074
  • CVEs / upstream IDs: CVE-2026-18300, ZDI-26-453, ZDI-CAN-29289
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

GEGL is a GNOME/GIMP image-processing desktop component, with no Flatcar shipment or usage evidence and no production SBOM match.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 49: media-gfx/gimp (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980075
  • CVEs / upstream IDs: CVE-2026-18301, CVE-2026-18302, CVE-2026-18303, CVE-2026-18304, CVE-2026-18305, CVE-2026-18306, CVE-2026-18307, CVE-2026-18308, CVE-2026-18309
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

GIMP is a desktop graphical image editor and no production SBOM or Flatcar usage evidence shows it is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 50: linux kernel (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/07/21/8
  • CVEs / upstream IDs: CVE-2026-31431, CVE-2026-53360, CVE-2026-63794, CVE-2026-64113, CVE-2026-64061, CVE-2026-63887, CVE-2026-63886, CVE-2026-63795, CVE-2026-63911, CVE-2026-64142, CVE-2026-63920, CVE-2026-64032, CVE-2026-63970, CVE-2026-64026
  • CVSS: 7.8
  • Flatcar relevance: kernel_regular_update_flow (scope: production)
  • Recommendation: kernel_regular_update_flow (confidence: high)
  • SBOM matches: linux-kernel 6.12.95-flatcar (exact_name)
  • Existing issue matches: none

Kernel CVEs are not tracked as normal Flatcar advisory issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: routed to the regular kernel update flow (no advisory issue)

Group 51: powerdns-recursor (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/07/22/6
  • CVEs / upstream IDs: CVE-2026-52688, CVE-2026-52686
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: github.com/miekg/dns v1.1.61 (unique_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-triage/reviewSecurity-triage generated review issue (approval required)security-triage/review-appliedSecurity-triage review actions have been applied

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions