Skip to content

Security triage review: 2026-08-18 (part 14/20) #283

Description

@github-actions

Automated Flatcar security-triage review batch 32105957657, part 14 of 20.

Run metadata

Summary

This part contains 17 decision group(s).

Recommendation Count
discovery_create_issue 4
discovery_ignore 11
discovery_update_issue 2
Confidence Count
high 10
low 1
medium 6
Severity Count
HIGH 1
n/a 16

Whole batch: 420 decision group(s) across 20 part(s).

Recommendation Count
cleanup_keep_open 34
discovery_create_issue 70
discovery_ignore 259
discovery_kernel_routing 1
discovery_update_issue 56
Confidence Count
high 251
low 84
medium 85
Severity Count
CRITICAL 4
HIGH 11
MEDIUM 8
n/a 397

How to use this review

  • Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
  • Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
  • Close this issue with reason Completed to apply every checked, conflict-free action.
  • Close this issue as Not planned (or leave it open) to take no automated action at all.
  • Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.

Decision groups

Group 264: net-misc/rsync (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980780
  • CVEs / upstream IDs: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786, CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791, CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795, CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799, CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803, CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455, CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459, CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463, CVE-2026-70464
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: net-misc/rsync 3.4.4 (exact_name)
  • Existing issue matches: update: rsync #229 (open): update: rsync

Production SBOM confirms rsync 3.4.4, while Gentoo tracks 33 new rsync CVEs fixed in 3.5.0; open issue #229 already covers rsync but not these CVEs or the new critical daemon/path-handling context.

Proposed additive update for action disc-ca252c4e466e90b31f5c (issue #229)
  • Add CVEs: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786, CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791, CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795, CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799, CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803, CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455, CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459, CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463, CVE-2026-70464
  • Add refmap.gentoo: https://bugs.gentoo.org/980780, http://bugs.gentoo.org/show_bug.cgi?id=978280, http://bugs.gentoo.org/show_bug.cgi?id=975525, http://bugs.gentoo.org/show_bug.cgi?id=948106
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): Rsync 3.5.0 fixes 33 security issues involving symlink and path traversal races, daemon protocol access-control and denial-of-service flaws, command or argument injection, TLS authentication, memory corruption, and related robustness issues.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786, CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791, CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795, CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799, CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803, CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455, CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459, CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463, CVE-2026-70464
- Add Gentoo aliases/CVEs: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786, CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791, CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795, CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799, CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803, CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455, CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459, CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463, CVE-2026-70464
- Add upstream context: Rsync 3.5.0 fixes 33 security issues involving symlink and path traversal races, daemon protocol access-control and denial-of-service flaws, command or argument injection, TLS authentication, memory corruption, and related robustness issues.
- Review Gentoo severity: critical
- Review upstream references: http://bugs.gentoo.org/show_bug.cgi?id=978280, http://bugs.gentoo.org/show_bug.cgi?id=975525, http://bugs.gentoo.org/show_bug.cgi?id=948106
- Review Bugzilla description: https://download.samba.org/pub/rsync/NEWS#3.5.0

"""
SECURITY FIXES:

This release fixes 33 security issues found during a focused audit of rsync's path handling and daemon protocol, a companion daemon-protocol fuzzing pass, and reports from external researchers -⁠-⁠ plus several robustness harde...
- Review Bugzilla comment #1 by sam at 2026-08-13T00:33:23Z: Continued:
"""
    CVE-2026-70456 (HIGH): an out-of-bounds heap write in read_args() when the peer's argument count lands exactly on maxargs -⁠-⁠ the trailing NULL went one past the end of the array.

    CVE-2026-70457 (MEDIUM): an attacker-chosen-offset write in parse_size_arg()'s error formatt...
- Review Bugzilla comment #2 by infra-gitbot at 2026-08-13T00:46:59Z: The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=513c488fcaedcdfe09261cea8540065c93eb33c0

commit 513c488fcaedcdfe09261cea8540065c93eb33c0
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2026-08-13 00:43:51 +0000
Commit:     Sam Jame...
- Review Bugzilla comment #3 by sam at 2026-08-14T01:50:20Z: Need to wait for https://github.com/RsyncProject/rsync/issues/1053 and https://github.com/RsyncProject/rsync/issues/1050 to be fixed at least, as well as the https://github.com/RsyncProject/rsync/issues/1045 test bug.

New Bugzilla comments in the processing window:
- Review Bugzilla comment #1 by sam at 2026-08-13T00:33:23Z: Continued:
"""
    CVE-2026-70456 (HIGH): an out-of-bounds heap write in read_args() when the peer's argument count lands exactly on maxargs -⁠-⁠ the trailing NULL went one past the end of the array.

    CVE-2026-70457 (MEDIUM): an attacker-chosen-offset write in parse_size_arg()'s error formatt...
- Review Bugzilla comment #2 by infra-gitbot at 2026-08-13T00:46:59Z: The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=513c488fcaedcdfe09261cea8540065c93eb33c0

commit 513c488fcaedcdfe09261cea8540065c93eb33c0
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2026-08-13 00:43:51 +0000
Commit:     Sam Jame...
- Review Bugzilla comment #3 by sam at 2026-08-14T01:50:20Z: Need to wait for https://github.com/RsyncProject/rsync/issues/1053 and https://github.com/RsyncProject/rsync/issues/1050 to be fixed at least, as well as the https://github.com/RsyncProject/rsync/issues/1045 test bug.

Source: https://bugs.gentoo.org/980780

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 265: flatpak (discovery, source: gentoo)

Flatpak is a desktop-oriented application sandbox/runtime and there is no evidence that it is shipped or used by Flatcar; no production SBOM match exists.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 266: www-client/chromium and listed Chromium-based browser packages (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980799
  • CVEs / upstream IDs: CVE-2026-19556, CVE-2026-19557, CVE-2026-19558, CVE-2026-19559, CVE-2026-19560
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c (ambiguous_substring); sys-apps/sed 4.10 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 267: net-im/zoom (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980808
  • CVEs / upstream IDs: CVE-2026-53413, CVE-2026-53414, CVE-2026-53415
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

This concerns the Zoom Linux desktop client, which is outside Flatcar's server-focused package scope and has no production SBOM evidence of shipment.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 268: dev-libs/openssl (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980809
  • CVEs / upstream IDs: CVE-2026-14456
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: high)
  • SBOM matches: dev-libs/openssl 3.5.7 (exact_name)
  • Existing issue matches: none

Production SBOM contains dev-libs/openssl 3.5.7, which is in the affected OpenSSL 3.5 branch for CVE-2026-14456; no existing matching issue was provided.

Exact proposed issue for action disc-35908800c0c10272f68a

Title: update: dev-libs/openssl

Name: dev-libs/openssl
CVEs: CVE-2026-14456
CVSSs: n/a
Action Needed: TBD
Summary: OpenSSL QUIC listeners can experience unbounded memory growth when processing many valid Initial packets for unknown destination connection IDs, potentially causing denial of service. OpenSSL 4.0, 3.6, and 3.5 are affected; 3.4 and older listed branches are not affected.

refmap.gentoo: https://bugs.gentoo.org/980809

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: dev-libs/openssl

Group 269: libgit2 (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980827
  • CVEs / upstream IDs: CVE-2026-5917
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: dev-vcs/git 2.54.0 (unique_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 270: zip (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980838
  • CVEs / upstream IDs: TBD
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: high)
  • SBOM matches: app-arch/zip 3.0-r7 (exact_name)
  • Existing issue matches: none

The production SBOM contains app-arch/zip 3.0-r7, which is within Gentoo's affected range (<3.0_p16). The issue is a command injection in zip -T when processing an attacker-controlled archive filename; no existing Flatcar issue match is present.

Exact proposed issue for action disc-700b69c6e3d779fa76f7

Title: update: zip

Name: zip
CVEs: TBD
CVSSs: n/a
Action Needed: TBD
Summary: Info-ZIP zip command injection in the -T integrity-test option when an attacker controls the archive filename.

refmap.gentoo: https://bugs.gentoo.org/980838

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: zip

Group 271: graphicsmagick (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980840
  • CVEs / upstream IDs: CVE-2026-42050, CVE-2026-61870, GHSA-7mxf-ff4f-jj7p, GENTOO BUG 980840
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

GraphicsMagick is not evidenced in the Flatcar production SBOM or other Flatcar package/usage evidence; it is a graphics/image-processing package and the source issue includes X11/display-related context.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 272: croc (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980854
  • CVEs / upstream IDs: 980854
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The evidence identifies croc as affected, but provides no indication that Flatcar ships or uses it, and no production SBOM match exists.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 273: dev-lang/go (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980862
  • CVEs / upstream IDs: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: unknown)
  • Recommendation: update_existing_issue (confidence: medium)
  • SBOM matches: cloud.google.com/go v0.121.6 (exact_name); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (exact_name); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.7 (exact_name)
  • Existing issue matches: update: dev-lang/go #64 (open): update: dev-lang/go

Open issue #64 already tracks dev-lang/go; this source adds ten distinct CVEs, updated affected/fixed versions (before 1.25.13 and 1.26.6), and new Gentoo/Openwall references that should be incorporated rather than creating a duplicate.

Proposed additive update for action disc-021d58320efd8cf9f15b (issue #64)

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865
- Add Gentoo aliases/CVEs: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865
- Add upstream context: Go 1.25.13 and 1.26.6 fix ten vulnerabilities affecting module transparency verification, XML/ASN.1 recursion, HTTP/2 timeout handling, URL path resolution, DNS SVCB parsing, TLS handshakes, JavaScript templating, and IDNA processing.
- Review Gentoo severity: normal (source: https://www.openwall.com/lists/oss-security/2026/08/13/13)
- Review upstream references: https://www.openwall.com/lists/oss-security/2026/08/13/13
- Review Bugzilla description: """

Hello gophers,

We have just released Go versions 1.26.6 and 1.25.13, minor point releases.

These releases include 10 security fixes following the security policy
<https://go.dev/doc/security/policy>:

   * x/mod/sumdb/tlog: fix transparency log tile verification bypass

     A malicious GO...
- Review Bugzilla comment #1 by infra-gitbot at 2026-08-15T00:20:32Z: The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c45cbced5d30bb660923ee14e58ef5d871653658

commit c45cbced5d30bb660923ee14e58ef5d871653658
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2026-08-15 00:11:34 +0000
Commit:     Sam Jame...

New Bugzilla comments in the processing window:
- Review Bugzilla comment #1 by infra-gitbot at 2026-08-15T00:20:32Z: The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c45cbced5d30bb660923ee14e58ef5d871653658

commit c45cbced5d30bb660923ee14e58ef5d871653658
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2026-08-15 00:11:34 +0000
Commit:     Sam Jame...

Source: https://bugs.gentoo.org/980862

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 274: dev-libs/botan (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980865
  • CVEs / upstream IDs: GH #5815, GH #5839, GH #5838, GH #5820, GH #5629, GH #5805
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-6fbbb09c82dfa2f7d8f6

Title: update: dev-libs/botan

Name: dev-libs/botan
CVEs: GH #5815, GH #5839, GH #5838, GH #5820, GH #5629, GH #5805
CVSSs: n/a
Action Needed: update target
Summary: Botan 3.13.0 fixes multiple security issues, including blind SSRF in OCSP processing, RNG seeding errors, 32-bit Scrypt integer overflow, DN name-constraint validation flaws, and an FFI integer overflow.

refmap.gentoo: https://bugs.gentoo.org/980865

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: dev-libs/botan
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 275: dev-libs/xapian (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980873
  • CVEs / upstream IDs: 980873
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: ../api (devel) (ambiguous_substring); ../api (devel) (ambiguous_substring); github.com/containerd/containerd/api v1.10.0 (ambiguous_substring); github.com/containerd/containerd/api v1.10.0 (ambiguous_substring); github.com/containerd/containerd/api v1.10.0 (ambiguous_substring); github.com/containerd/containerd/api v1.10.0 (ambiguous_substring); github.com/containerd/containerd/api v1.8.0 (ambiguous_substring); github.com/moby/moby/api v1.52.0 (ambiguous_substring); github.com/moby/moby/api v1.52.0 (ambiguous_substring); google.golang.org/api v0.248.0 (ambiguous_substring); google.golang.org/api v0.252.0 (ambiguous_substring); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (ambiguous_substring); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (ambiguous_substring); google.golang.org/genproto/googleapis/api v0.0.0-20241021214115-324edc3d5d38 (ambiguous_substring); google.golang.org/genproto/googleapis/api v0.0.0-20250218202821-56aae31c358a (ambiguous_substring); google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c (ambiguous_substring); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (ambiguous_substring); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (ambiguous_substring); google.golang.org/genproto/googleapis/api v0.0.0-20251029180050-ab9386a59fda (ambiguous_substring); k8s.io/api v0.31.2 (ambiguous_substring); k8s.io/api v0.33.0-rc.0 (ambiguous_substring); k8s.io/api v0.34.1 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 276: dev-perl/DBI (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980944
  • CVEs / upstream IDs: CVE-2026-73193, CVE-2026-73194
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

dev-perl/DBI is not present in the provided production SBOM evidence, and there is no evidence that Flatcar ships or uses this Perl module.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 277: app-arch/unzip (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980955
  • CVEs / upstream IDs: CAN-2026-2034440, CAN-2026-2034442, CAN-2026-2034443
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: medium)
  • SBOM matches: app-arch/unzip 6.0_p29-r2 (exact_name)
  • Existing issue matches: none

The production SBOM contains app-arch/unzip 6.0_p29-r2, and the Gentoo vulnerability entry identifies multiple CVEs affecting app-arch/unzip versions before 6.0_p31. No existing matching issue is present.

Exact proposed issue for action disc-ef4645ac11530e8975f3

Title: update: app-arch/unzip

Name: app-arch/unzip
CVEs: CAN-2026-2034440, CAN-2026-2034442, CAN-2026-2034443
CVSSs: n/a
Action Needed: TBD
Summary: Multiple unzip vulnerabilities associated with version 6.0_p31; issues were moved from Gentoo bug 980838.

refmap.gentoo: https://bugs.gentoo.org/980955

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: app-arch/unzip

Group 278: net-analyzer/tcpreplay (discovery, source: gentoo)

tcpreplay is not evidenced as shipped or used by Flatcar; production SBOM has no matching package and no existing Flatcar issue is present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 279: putty (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980976
  • CVEs / upstream IDs: TBD
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: acct-group/tty 0-r3 (unique_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 280: htop (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/980985
  • CVEs / upstream IDs: CVE-2024-37676
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

htop is not present in the provided production SBOM evidence, and no other evidence shows that Flatcar ships or uses it.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-triage/reviewSecurity-triage generated review issue (approval required)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions