Automated Flatcar security-triage review batch 30521416158, part 2 of 10.
Run metadata
Summary
This part contains 31 decision group(s).
Recommendation
Count
discovery_create_issue
2
discovery_ignore
27
discovery_kernel_routing
1
discovery_update_issue
1
Confidence
Count
high
18
low
2
medium
11
Severity
Count
CRITICAL
1
HIGH
3
n/a
27
Whole batch: 270 decision group(s) across 10 part(s).
Recommendation
Count
cleanup_keep_open
16
discovery_create_issue
31
discovery_ignore
214
discovery_kernel_routing
4
discovery_update_issue
5
Confidence
Count
high
169
low
34
medium
67
Severity
Count
CRITICAL
4
HIGH
7
MEDIUM
3
n/a
256
How to use this review
Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
Close this issue with reason Completed to apply every checked, conflict-free action.
Close this issue as Not planned (or leave it open) to take no automated action at all.
Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.
Decision groups
Group 21: dev-lang/go (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979580
CVEs / upstream IDs: CVE-2026-42505 , GO ISSUE 79282
CVSS: n/a
Flatcar relevance: relevant (scope: unknown)
Recommendation: update_existing_issue (confidence: medium)
SBOM matches: cloud.google.com/go v0.121.6 (exact_name); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (exact_name); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.7 (exact_name)
Existing issue matches: update: dev-lang/go #64 (open): update: dev-lang/go
Open issue #64 already tracks dev-lang/go and Gentoo bug 979580; CVE-2026-42505 , its ECH privacy-leak description, affected/fixed versions (before 1.25.12/1.26.5), and references are new information not present in that issue.
Proposed additive update for action disc-490ad96b4dcc17654e1b (issue #64 )
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2026-42505, GO ISSUE 79282
- Add Gentoo aliases/CVEs: CVE-2026-42505
- Add upstream context: Go crypto/tls Encrypted Client Hello leaked pre-shared key identities to passive network observers, potentially revealing the server hostname despite ECH.
- Review Gentoo severity: trivial (source: https://groups.google.com/g/golang-dev/c/aid3V6iXQ0Y)
- Review upstream references: https://groups.google.com/g/golang-dev/c/aid3V6iXQ0Y, http://bugs.gentoo.org/show_bug.cgi?id=979521, https://go.dev/issue/79282, https://codeberg.org/gentoo/gentoo/pulls/1510
- Review Bugzilla description: Quoting from https://groups.google.com/g/golang-dev/c/aid3V6iXQ0Y:
We have just released Go versions 1.26.5 and 1.25.12, minor point releases.
These releases include 2 security fixes following the security policy:
os: Root escape via symlink plus trailing slash
On Unix systems, op...
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=24dac47784949a95b4ad43c5c28b7dd0616fc36e
commit 24dac47784949a95b4ad43c5c28b7dd0616fc36e
Author: Holger Hoffstätte holger@applied-asynchrony.com
AuthorDate: 2026-07-23 09:10:48 +00...
New Bugzilla comments in the processing window:
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=24dac47784949a95b4ad43c5c28b7dd0616fc36e
commit 24dac47784949a95b4ad43c5c28b7dd0616fc36e
Author: Holger Hoffstätte holger@applied-asynchrony.com
AuthorDate: 2026-07-23 09:10:48 +00...
Source: https://bugs.gentoo.org/979580
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
</details>
Choose at most one (leave all unchecked to take no action for this group):
- [ ] Update existing issue #64 with new upstream context <!-- security-triage:action-id:disc-490ad96b4dcc17654e1b -->
### Group 22: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin (discovery, source: gentoo)
- Source URL: `https://bugs.gentoo.org/979647`
- CVEs / upstream IDs: CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057, CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147, CVE-2026-41254
- CVSS: 5.3, 5.9, 3.7, 7.5, 7.4, 6.5
- Flatcar relevance: **needs_manual_review** (scope: unknown)
- Recommendation: **needs_manual_review** (confidence: low)
- SBOM matches: none
- Existing issue matches: none
> LLM relevance decision requested manual review.
- Safety/ambiguity notes: LLM relevance decision requested manual review.
<details><summary>Exact proposed issue for action <code>disc-bd139335fe9a8f719d8a</code></summary>
Title: `update: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin`
```text
Name: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin
CVEs: CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057, CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147, CVE-2026-41254
CVSSs: 5.3, 5.9, 3.7, 7.5, 7.4, 6.5
Action Needed: TBD
Summary: OpenJDK vulnerability advisory covering multiple security issues in core, client, security, and scripting libraries; Gentoo added fixes for OpenJDK 8, 11, 17, 21, and 25, while binary and JRE binary updates were not yet available.
refmap.gentoo: https://bugs.gentoo.org/979647
Labels: advisory, security, cvss/HIGH
Choose at most one (leave all unchecked to take no action for this group):
Group 23: www-client/firefox and www-client/firefox-bin (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979654
CVEs / upstream IDs: CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16364 , CVE-2026-16365 , CVE-2026-16366 , CVE-2026-16367 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16370 , CVE-2026-16371 , CVE-2026-16372 , CVE-2026-16373 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16376 , CVE-2026-16377 , CVE-2026-16378 , CVE-2026-16379 , CVE-2026-16380 , CVE-2026-16381 , CVE-2026-16382 , CVE-2026-16383 , CVE-2026-16384 , CVE-2026-16385 , CVE-2026-16386 , CVE-2026-16387 , CVE-2026-16388 , CVE-2026-16389 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16392 , CVE-2026-16393 , CVE-2026-16394 , CVE-2026-16395 , CVE-2026-16396 , CVE-2026-16397 , CVE-2026-16398 , CVE-2026-16399 , CVE-2026-16400 , CVE-2026-16401 , CVE-2026-16402 , CVE-2026-16403 , CVE-2026-16404 , CVE-2026-16405 , CVE-2026-16406 , CVE-2026-16407 , CVE-2026-16408 , CVE-2026-16409 , CVE-2026-16410 , CVE-2026-16411 , CVE-2026-16412
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The advisory affects Firefox desktop browser packages, which are not evidenced as shipped or used by Flatcar; no production SBOM match exists.
Choose at most one (leave all unchecked to take no action for this group):
Group 24: www-client/chromium, www-client/google-chrome, www-client/microsoft-edge, www-client/opera, www-client/opera-gx, www-client/vivaldi, www-client/vivaldi-snapshot (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979667
CVEs / upstream IDs: CVE-2026-16413 , CVE-2026-16414 , CVE-2026-16415 , CVE-2026-16416 , CVE-2026-16417 , CVE-2026-16418 , CVE-2026-16419 , CVE-2026-16420 , CVE-2026-16421 , CVE-2026-16422 , CVE-2026-16423 , CVE-2026-16424
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The advisory concerns Chromium-based desktop browser packages, which are not relevant server packages for Flatcar, and there is no evidence that any affected browser is shipped or used by Flatcar.
Choose at most one (leave all unchecked to take no action for this group):
Group 25: knot-resolver (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979670
CVEs / upstream IDs: CVE-2026-66374
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
Knot Resolver is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches.
Choose at most one (leave all unchecked to take no action for this group):
Group 26: weechat (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979673
CVEs / upstream IDs: GHSA-68ff-gq39-pqjm
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
WeeChat is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches.
Choose at most one (leave all unchecked to take no action for this group):
Group 27: net-dns/pdns-recursor (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979682
CVEs / upstream IDs: CVE-2026-52688 , CVE-2026-52686 , CVE-2026-62686
CVSS: 7.5, 3.7
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: github.com/miekg/dns v1.1.61 (unique_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 28: dev-libs/aws-c-http; dev-libs/aws-c-event-stream; dev-cpp/aws-sdk-cpp (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979685
CVEs / upstream IDs: CVE-2026-12043, CVE-2026-5190
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: go.opentelemetry.io/auto/sdk v1.1.0 (ambiguous_substring); go.opentelemetry.io/auto/sdk v1.1.0 (ambiguous_substring); go.opentelemetry.io/auto/sdk v1.2.1 (ambiguous_substring); go.opentelemetry.io/auto/sdk v1.2.1 (ambiguous_substring); go.opentelemetry.io/auto/sdk v1.2.1 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.31.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.31.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.35.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.37.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.38.0 (ambiguous_substring); go.opentelemetry.io/otel/sdk v1.38.0 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 29: thunderbird, thunderbird-bin (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979691
CVEs / upstream IDs: CVE-2026-14899 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16364 , CVE-2026-16365 , CVE-2026-16366 , CVE-2026-16367 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16370 , CVE-2026-16371 , CVE-2026-16372 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16376 , CVE-2026-16377 , CVE-2026-16378 , CVE-2026-16379 , CVE-2026-16380 , CVE-2026-16381 , CVE-2026-16382 , CVE-2026-16383 , CVE-2026-16384 , CVE-2026-16385 , CVE-2026-16386 , CVE-2026-16387 , CVE-2026-16388 , CVE-2026-16389 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16392 , CVE-2026-16393 , CVE-2026-16394 , CVE-2026-16395 , CVE-2026-16396 , CVE-2026-16398 , CVE-2026-16399 , CVE-2026-16400 , CVE-2026-16401 , CVE-2026-16402 , CVE-2026-16403 , CVE-2026-16405 , CVE-2026-16406 , CVE-2026-16407 , CVE-2026-16408 , CVE-2026-16409 , CVE-2026-16410 , CVE-2026-16411 , CVE-2026-16412
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
This concerns Thunderbird desktop email-client packages, with no evidence that Flatcar ships or uses them.
Choose at most one (leave all unchecked to take no action for this group):
Group 30: rsyslog (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979705
CVEs / upstream IDs: GHSA-cj5r-wh2m-7w29
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); golang.org/x/sys v0.23.0 (ambiguous_substring); golang.org/x/sys v0.29.0 (ambiguous_substring); golang.org/x/sys v0.29.0 (ambiguous_substring); golang.org/x/sys v0.29.0 (ambiguous_substring); golang.org/x/sys v0.32.0 (ambiguous_substring); golang.org/x/sys v0.32.0 (ambiguous_substring); golang.org/x/sys v0.32.0 (ambiguous_substring); golang.org/x/sys v0.37.0 (ambiguous_substring); golang.org/x/sys v0.38.0 (ambiguous_substring); golang.org/x/sys v0.38.0 (ambiguous_substring); golang.org/x/sys v0.46.0 (ambiguous_substring); golang.org/x/sys v0.46.0 (ambiguous_substring); golang.org/x/sys v0.46.0 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 31: dev-python/gitpython (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979713
CVEs / upstream IDs: GHSA-94p4-4cq8-9g67
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: dev-vcs/git 2.53.0 (unique_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 32: dev-qt/qtbase (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979715
CVEs / upstream IDs: CVE-2026-15037
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
Qt/qtbase is a desktop-oriented graphical stack component, and the evidence provides no indication that Flatcar ships or uses it.
Choose at most one (leave all unchecked to take no action for this group):
Group 33: net-libs/webkit-gtk (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979717
CVEs / upstream IDs: CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
WebKitGTK/WPE WebKit is a graphical web-rendering stack, which is outside Flatcar's minimal server-focused package scope, and there is no production SBOM evidence that it is shipped or used.
Choose at most one (leave all unchecked to take no action for this group):
Group 34: dev-perl/YAML-Syck (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979724
CVEs / upstream IDs: CVE-2026-13713, CVE-2026-4177, CVE-2026-5089, CVE-2026-57075, CVE-2026-57076, CVE-2026-57077
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: sigs.k8s.io/yaml v1.4.0 (ambiguous_substring); sigs.k8s.io/yaml v1.4.0 (ambiguous_substring); sigs.k8s.io/yaml v1.4.0 (ambiguous_substring); sigs.k8s.io/yaml v1.6.0 (ambiguous_substring); sigs.k8s.io/yaml v1.6.0 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 35: dev-perl/XML-LibXML (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979725
CVEs / upstream IDs: CVE-2026-8177
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
CVE-2026-8177 affects the Perl module dev-perl/XML-LibXML, and the evidence provides no indication that this package is shipped or used by Flatcar.
Choose at most one (leave all unchecked to take no action for this group):
Group 36: dev-perl/Plack (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979750
CVEs / upstream IDs: CVE-2025-40926
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The affected Perl package dev-perl/Plack is not present in the provided production SBOM evidence, and there is no evidence that Flatcar ships or uses Plack::Middleware::Session::Simple.
Choose at most one (leave all unchecked to take no action for this group):
Group 37: www-client/chromium and related Chromium-based browser packages (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979752
CVEs / upstream IDs: CVE-2026-16804, CVE-2026-16805, CVE-2026-16806, CVE-2026-16807
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); sys-apps/sed 4.9-r1 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 38: dev-ruby/zlib (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979772
CVEs / upstream IDs: CVE-2026-27820, GHSA-g857-hhfv-j68w
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: sys-libs/zlib 1.3.2-r1 (exact_name); virtual/zlib 1.3.1-r1 (exact_name)
Existing issue matches: none
CVE-2026-27820 affects the Ruby dev-ruby/zlib gem, while the production SBOM only contains the distinct native sys-libs/zlib library and virtual/zlib provider; no Flatcar Ruby-gem usage is evidenced.
Choose at most one (leave all unchecked to take no action for this group):
Group 39: dev-ruby/erb (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979773
CVEs / upstream IDs: CVE-2026-41316, GHSA-q339-8rmv-2mhv
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
This is a Ruby/ERB application-ecosystem vulnerability, and the bundle provides no evidence that Ruby or the erb gem is shipped or used by Flatcar production images.
Choose at most one (leave all unchecked to take no action for this group):
Group 40: dev-ruby/net-imap (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979774
CVEs / upstream IDs: CVE-2026-42245, CVE-2026-42246, CVE-2026-42256, CVE-2026-42257, CVE-2026-42258, CVE-2026-47240, CVE-2026-47241, CVE-2026-47242, GHSA-46q3-7gv7-qmgg , GHSA-75xq-5h9v-w6px , GHSA-87pf-fpwv-p7m7 , GHSA-8p34-64r3-mwg8 , GHSA-c4fp-cxrr-mj66 , GHSA-hm49-wcqc-g2xg , GHSA-q2mw-fvj9-vvcw , GHSA-vcgp-9326-pqcp
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.38.0 (ambiguous_substring); golang.org/x/net v0.39.0 (ambiguous_substring); golang.org/x/net v0.39.0 (ambiguous_substring); golang.org/x/net v0.43.0 (ambiguous_substring); golang.org/x/net v0.46.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 41: dev-lang/ruby (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979775
CVEs / upstream IDs: CVE-2026-46727
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
Ruby is an unrelated application-language runtime for Flatcar absent evidence that it is shipped or used; no production SBOM match or existing Flatcar issue is present.
Choose at most one (leave all unchecked to take no action for this group):
Group 42: dev-java/openjfx (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979804
CVEs / upstream IDs: 979804
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The advisory concerns the desktop JavaFX package dev-java/openjfx and its build-time bundled Gradle; no Flatcar SBOM or other evidence shows this package is shipped or used.
Choose at most one (leave all unchecked to take no action for this group):
Group 43: media-radio/svxlink (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/979827
CVEs / upstream IDs: GHSA-pc2g-2p95-4cr5
CVSS: 9.8
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
svxlink is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches or existing Flatcar issues.
Choose at most one (leave all unchecked to take no action for this group):
Group 44: dev-libs/log4cxx (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/980048
CVEs / upstream IDs: CVE-2026-40023
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring); github.com/containerd/log v0.1.0 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 45: dev-java/bcprov (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/980052
CVEs / upstream IDs: CVE-2026-12185, CVE-2026-12802, CVE-2026-12803, CVE-2026-12816, CVE-2026-12817, CVE-2026-12852, CVE-2026-12860, CVE-2026-13506, CVE-2026-13586, CVE-2026-14682, CVE-2026-15505, CVE-2026-58059, CVE-2026-58060, CVE-2026-58061, CVE-2026-58062, CVE-2026-58063, CVE-2026-59638, CVE-2026-59639, CVE-2026-59640, CVE-2026-59641, CVE-2026-59642, CVE-2026-59643, CVE-2026-59644, CVE-2026-59645, CVE-2026-59646, CVE-2026-59647, CVE-2026-59648, CVE-2026-59649, CVE-2026-59650, CVE-2026-59651, CVE-2026-59652, CVE-2026-8763
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The advisory concerns dev-java/bcprov, but the bundle provides no evidence that Bouncy Castle or a Java runtime using it is shipped or used by Flatcar, and there are no production SBOM matches.
Choose at most one (leave all unchecked to take no action for this group):
Group 46: libarchive (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/980054
CVEs / upstream IDs: 980054
CVSS: n/a
Flatcar relevance: needs_manual_review (scope: production)
Recommendation: needs_manual_review (confidence: low)
SBOM matches: app-arch/libarchive 3.8.7 (exact_name)
Existing issue matches: none
LLM relevance decision requested manual review.
Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-d5a361fc777114d333ae
Title: update: libarchive
Name: libarchive
CVEs: TBD
CVSSs: n/a
Action Needed: TBD
Summary: Gentoo tracks unspecified multiple libarchive vulnerabilities associated with the 3.8.9 security and bugfix release; specific issues and identifiers are not provided.
refmap.gentoo: https://bugs.gentoo.org/980054
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 47: dev-ruby/activestorage (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/980072
CVEs / upstream IDs: CVE-2026-66066
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: cloud.google.com/go/storage v1.57.0 (unique_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 48: gegl (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/980074
CVEs / upstream IDs: CVE-2026-18300, ZDI-26-453, ZDI-CAN-29289
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
GEGL is a GNOME/GIMP image-processing desktop component, with no Flatcar shipment or usage evidence and no production SBOM match.
Choose at most one (leave all unchecked to take no action for this group):
Group 49: media-gfx/gimp (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/980075
CVEs / upstream IDs: CVE-2026-18301, CVE-2026-18302, CVE-2026-18303, CVE-2026-18304, CVE-2026-18305, CVE-2026-18306, CVE-2026-18307, CVE-2026-18308, CVE-2026-18309
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
GIMP is a desktop graphical image editor and no production SBOM or Flatcar usage evidence shows it is shipped or used by Flatcar.
Choose at most one (leave all unchecked to take no action for this group):
Group 50: linux kernel (discovery, source: oss_security)
Source URL: https://www.openwall.com/lists/oss-security/2026/07/21/8
CVEs / upstream IDs: CVE-2026-31431, CVE-2026-53360, CVE-2026-63794, CVE-2026-64113, CVE-2026-64061, CVE-2026-63887, CVE-2026-63886, CVE-2026-63795, CVE-2026-63911, CVE-2026-64142, CVE-2026-63920, CVE-2026-64032, CVE-2026-63970, CVE-2026-64026
CVSS: 7.8
Flatcar relevance: kernel_regular_update_flow (scope: production)
Recommendation: kernel_regular_update_flow (confidence: high)
SBOM matches: linux-kernel 6.12.95-flatcar (exact_name)
Existing issue matches: none
Kernel CVEs are not tracked as normal Flatcar advisory issues.
Choose at most one (leave all unchecked to take no action for this group):
Group 51: powerdns-recursor (discovery, source: oss_security)
Source URL: https://www.openwall.com/lists/oss-security/2026/07/22/6
CVEs / upstream IDs: CVE-2026-52688 , CVE-2026-52686
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: github.com/miekg/dns v1.1.61 (unique_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.
Automated Flatcar security-triage review batch
30521416158, part 2 of 10.Run metadata
flatcar/security-triageflatcar/security-triage40c0053d25dfcb7f976e1a442bf00424fd358326Summary
This part contains 31 decision group(s).
Whole batch: 270 decision group(s) across 10 part(s).
How to use this review
Decision groups
Group 21: dev-lang/go (discovery, source: gentoo)
https://bugs.gentoo.org/979580Proposed additive update for action
disc-490ad96b4dcc17654e1b(issue #64)Comment to post:
We have just released Go versions 1.26.5 and 1.25.12, minor point releases.
These releases include 2 security fixes following the security policy:
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=24dac47784949a95b4ad43c5c28b7dd0616fc36e
commit 24dac47784949a95b4ad43c5c28b7dd0616fc36e
Author: Holger Hoffstätte holger@applied-asynchrony.com
AuthorDate: 2026-07-23 09:10:48 +00...
New Bugzilla comments in the processing window:
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=24dac47784949a95b4ad43c5c28b7dd0616fc36e
commit 24dac47784949a95b4ad43c5c28b7dd0616fc36e
Author: Holger Hoffstätte holger@applied-asynchrony.com
AuthorDate: 2026-07-23 09:10:48 +00...
Source: https://bugs.gentoo.org/979580
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
Labels: advisory, security, cvss/HIGH
Choose at most one (leave all unchecked to take no action for this group):
Group 23: www-client/firefox and www-client/firefox-bin (discovery, source: gentoo)
https://bugs.gentoo.org/979654Choose at most one (leave all unchecked to take no action for this group):
Group 24: www-client/chromium, www-client/google-chrome, www-client/microsoft-edge, www-client/opera, www-client/opera-gx, www-client/vivaldi, www-client/vivaldi-snapshot (discovery, source: gentoo)
https://bugs.gentoo.org/979667Choose at most one (leave all unchecked to take no action for this group):
Group 25: knot-resolver (discovery, source: gentoo)
https://bugs.gentoo.org/979670Choose at most one (leave all unchecked to take no action for this group):
Group 26: weechat (discovery, source: gentoo)
https://bugs.gentoo.org/979673Choose at most one (leave all unchecked to take no action for this group):
Group 27: net-dns/pdns-recursor (discovery, source: gentoo)
https://bugs.gentoo.org/979682Choose at most one (leave all unchecked to take no action for this group):
Group 28: dev-libs/aws-c-http; dev-libs/aws-c-event-stream; dev-cpp/aws-sdk-cpp (discovery, source: gentoo)
https://bugs.gentoo.org/979685Choose at most one (leave all unchecked to take no action for this group):
Group 29: thunderbird, thunderbird-bin (discovery, source: gentoo)
https://bugs.gentoo.org/979691Choose at most one (leave all unchecked to take no action for this group):
Group 30: rsyslog (discovery, source: gentoo)
https://bugs.gentoo.org/979705Choose at most one (leave all unchecked to take no action for this group):
Group 31: dev-python/gitpython (discovery, source: gentoo)
https://bugs.gentoo.org/979713Choose at most one (leave all unchecked to take no action for this group):
Group 32: dev-qt/qtbase (discovery, source: gentoo)
https://bugs.gentoo.org/979715Choose at most one (leave all unchecked to take no action for this group):
Group 33: net-libs/webkit-gtk (discovery, source: gentoo)
https://bugs.gentoo.org/979717Choose at most one (leave all unchecked to take no action for this group):
Group 34: dev-perl/YAML-Syck (discovery, source: gentoo)
https://bugs.gentoo.org/979724Choose at most one (leave all unchecked to take no action for this group):
Group 35: dev-perl/XML-LibXML (discovery, source: gentoo)
https://bugs.gentoo.org/979725Choose at most one (leave all unchecked to take no action for this group):
Group 36: dev-perl/Plack (discovery, source: gentoo)
https://bugs.gentoo.org/979750Choose at most one (leave all unchecked to take no action for this group):
Group 37: www-client/chromium and related Chromium-based browser packages (discovery, source: gentoo)
https://bugs.gentoo.org/979752Choose at most one (leave all unchecked to take no action for this group):
Group 38: dev-ruby/zlib (discovery, source: gentoo)
https://bugs.gentoo.org/979772Choose at most one (leave all unchecked to take no action for this group):
Group 39: dev-ruby/erb (discovery, source: gentoo)
https://bugs.gentoo.org/979773Choose at most one (leave all unchecked to take no action for this group):
Group 40: dev-ruby/net-imap (discovery, source: gentoo)
https://bugs.gentoo.org/979774Choose at most one (leave all unchecked to take no action for this group):
Group 41: dev-lang/ruby (discovery, source: gentoo)
https://bugs.gentoo.org/979775Choose at most one (leave all unchecked to take no action for this group):
Group 42: dev-java/openjfx (discovery, source: gentoo)
https://bugs.gentoo.org/979804Choose at most one (leave all unchecked to take no action for this group):
Group 43: media-radio/svxlink (discovery, source: gentoo)
https://bugs.gentoo.org/979827Choose at most one (leave all unchecked to take no action for this group):
Group 44: dev-libs/log4cxx (discovery, source: gentoo)
https://bugs.gentoo.org/980048Choose at most one (leave all unchecked to take no action for this group):
Group 45: dev-java/bcprov (discovery, source: gentoo)
https://bugs.gentoo.org/980052Choose at most one (leave all unchecked to take no action for this group):
Group 46: libarchive (discovery, source: gentoo)
https://bugs.gentoo.org/980054Exact proposed issue for action
disc-d5a361fc777114d333aeTitle:
update: libarchiveLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 47: dev-ruby/activestorage (discovery, source: gentoo)
https://bugs.gentoo.org/980072Choose at most one (leave all unchecked to take no action for this group):
Group 48: gegl (discovery, source: gentoo)
https://bugs.gentoo.org/980074Choose at most one (leave all unchecked to take no action for this group):
Group 49: media-gfx/gimp (discovery, source: gentoo)
https://bugs.gentoo.org/980075Choose at most one (leave all unchecked to take no action for this group):
Group 50: linux kernel (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/07/21/8Choose at most one (leave all unchecked to take no action for this group):
Group 51: powerdns-recursor (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/07/22/6Choose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.