You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The report concerns CUPS printer/PPD validation, with no CVE identifier, no established affected/fixed upstream version range, and no evidence that CUPS is shipped or used by Flatcar production images.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 72: net-analyzer/wireshark (discovery, source: gentoo)
Exact proposed issue for action disc-6925b78930a8ea754a64
Title: update: unbound
Name: unbound
CVEs: CVE-2024-8508
CVSSs: n/a
Action Needed: TBD
Summary: Unbounded name compression in Unbound can lead to denial of service; a patch is reported to apply cleanly to versions 1.19.3 and 1.20.0.
refmap.gentoo: https://bugs.gentoo.org/941857
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Production SBOM confirms net-misc/curl 8.21.0, the same package affected by CVE-2024-11053; no existing matching issue is present.
Exact proposed issue for action disc-3db38879d376bf88dafe
Title: update: curl
Name: curl
CVEs: CVE-2024-11053
CVSSs: n/a
Action Needed: update target
Summary: curl may leak .netrc credentials to an HTTP redirect target when the target entry omits a password or both login and password.
refmap.gentoo: https://bugs.gentoo.org/946291
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
The production SBOM confirms app-editors/vim is shipped, and open issue #153 already tracks the same package but not CVE-2025-22134. Update it with this distinct CVE, advisory details, affected/fixed versions, and references; the shipped 9.1.1652-r2 version is newer than the 9.1.1003 fix.
Proposed additive update for action disc-95c4c8024737c971070b (issue #153)
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): Vim heap-buffer-overflow when switching buffers with visual mode active while executing :all; fixed in patch 9.1.1003.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2025-22134
- Add Gentoo aliases/CVEs: CVE-2025-22134
- Add upstream context: Vim heap-buffer-overflow when switching buffers with visual mode active while executing :all; fixed in patch 9.1.1003.
- Review Gentoo severity: normal (source: https://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v8)
- Review upstream references: https://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v8, https://bugs.gentoo.org/show_bug.cgi?id=961498, https://codeberg.org/gentoo/gentoo/pulls/284
- Review Bugzilla description: From $URL:
###
Summary
A heap-buffer-overflow with visual mode was found in Vim < 9.1.1003
Impact
When switching to other buffers using the :all command and visual mode
still being active, this may cause a heap-buffer overflow, because Vim
does not properly end visual mode and therefore may tr...
- Review Bugzilla comment #2 by bacs at 2026-08-16T11:05:23Z: glsa^ with 937126
New Bugzilla comments in the processing window:
- Review Bugzilla comment #2 by bacs at 2026-08-16T11:05:23Z: glsa^ with 937126
Source: https://bugs.gentoo.org/947924
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Update existing issue update: vim #153 with new upstream context
Exact proposed issue for action disc-6149e8906119d25ccf66
Title: update: dev-lang/go
Name: dev-lang/go
CVEs: CVE-2024-45336, CVE-2024-45341
CVSSs: n/a
Action Needed: update target
Summary: Go vulnerabilities involving sensitive headers being restored after cross-domain redirects and IPv6 zone IDs bypassing URI name constraints.
refmap.gentoo: https://bugs.gentoo.org/948232
Labels: advisory, security
Proposed additive update for action disc-4206141b65623d471353 (issue #64)
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): Go vulnerabilities involving sensitive headers being restored after cross-domain redirects and IPv6 zone IDs bypassing URI name constraints.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Flatcar production SBOM contains OpenSSL 3.5.7, which is newer than the listed fixed releases (3.3.3, 3.2.4, 3.1.8, and 3.0.16); no affected Flatcar version is evidenced.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 82: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin (discovery, source: gentoo)
CVE-2025-21502 affects OpenJDK/GraalVM packages, but the bundle provides no evidence that any affected Java package is shipped or used by Flatcar, and there are no production SBOM matches.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 83: net-dns/bind (discovery, source: gentoo)
The production SBOM confirms net-dns/bind is shipped, and open issue #61 already tracks this package but does not list CVE-2024-11187, CVE-2024-12705, or CVE-2025-40775. Update that existing issue rather than creating a duplicate; the shipped 9.20.23 is newer than the reported fixes.
Proposed additive update for action disc-915e12c0bd1a6f59d732 (issue #61)
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): Bind vulnerabilities causing resource exhaustion via DoH or large additional sections and denial of service through invalid TSIG messages; fixes are reported in 9.18.33, 9.20.5, and 9.21.4.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2024-11187, CVE-2024-12705, CVE-2025-40775
- Add Gentoo aliases/CVEs: CVE-2024-11187, CVE-2024-12705, CVE-2025-40775
- Add upstream context: Bind vulnerabilities causing resource exhaustion via DoH or large additional sections and denial of service through invalid TSIG messages; fixes are reported in 9.18.33, 9.20.5, and 9.21.4.
- Review Gentoo severity: normal (source: https://kb.isc.org/docs/aa-00913)
- Review upstream references: https://kb.isc.org/docs/aa-00913
- Review Bugzilla description: Two vulnerabilities (CVE-2024-11187,CVE-2024-12705) have been fixed in the latest updates of bind.
Fixed in 9.18.33,9.20.5,9.21.4.
- Review Bugzilla comment #7 by bacs at 2026-08-16T10:20:32Z: glsa^ with 936568
New Bugzilla comments in the processing window:
- Review Bugzilla comment #7 by bacs at 2026-08-16T10:20:32Z: glsa^ with 936568
Source: https://bugs.gentoo.org/949125
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Production SBOM confirms net-misc/curl 8.21.0; the Gentoo advisory identifies three curl CVEs fixed in 8.12.0, and no existing Flatcar issue match is present.
Exact proposed issue for action disc-c49d92d7003186c333c8
Title: update: net-misc/curl
Name: net-misc/curl
CVEs: CVE-2025-0167, CVE-2025-0665, CVE-2025-0725
CVSSs: n/a
Action Needed: update target
Summary: Curl vulnerabilities involving netrc/default credential leakage, eventfd double close, and a gzip integer overflow; the source states that curl 8.12.0 contains fixes.
refmap.gentoo: https://bugs.gentoo.org/949330
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Create new advisory issue: update: net-misc/curl
Group 85: curl (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/949342
CVEs / upstream IDs: CURL ISSUE 16197
CVSS: n/a
Flatcar relevance: relevant (scope: production)
Recommendation: ignore (confidence: high)
SBOM matches: net-misc/curl 8.21.0 (exact_name)
Existing issue matches: none
Flatcar ships production curl 8.21.0, which is newer than the reported 8.13.0 fix; no existing Flatcar issue requires updating.
Choose at most one (leave all unchecked to take no action for this group):
Exact proposed issue for action disc-776a79d63c4851103e98
Title: update: dev-lang/go
Name: dev-lang/go
CVEs: CVE-2025-22866, GO ISSUE 71383
CVSSs: n/a
Action Needed: update target
Summary: A variable-time instruction in Go's ppc64le P-256 elliptic-curve assembly leaks a small number of secret-scalar bits through a timing side channel; upstream states this is not believed sufficient to recover private keys in well-known protocols.
refmap.gentoo: https://bugs.gentoo.org/949405
Labels: advisory, security
Proposed additive update for action disc-a10b67cebf4b5d27cb38 (issue #64)
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): A variable-time instruction in Go's ppc64le P-256 elliptic-curve assembly leaks a small number of secret-scalar bits through a timing side channel; upstream states this is not believed sufficient to recover private keys in well-known protocols.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
libtasn1 is present in the production SBOM, but the shipped version is 4.21.0, which is newer than the stated fixed version 4.20.0; no evidence shows an affected Flatcar version.
Choose at most one (leave all unchecked to take no action for this group):
OpenSSL is shipped in the production SBOM, but the recorded production version is 3.5.7, which is newer than the listed fixed releases (3.1.8, 3.2.4, and 3.3.3) for CVE-2024-12797. The affected range is limited to OpenSSL >=3.1 before those fixes; no affected Flatcar production version is evidenced.
Choose at most one (leave all unchecked to take no action for this group):
Exact proposed issue for action disc-169d4e3496ca398a4f54
Title: update: dev-lang/go
Name: dev-lang/go
CVEs: CVE-2025-22870, GO ISSUE 71984
CVSSs: n/a
Action Needed: update target
Summary: Go proxy matching could improperly treat an IPv6 zone ID as a hostname component, allowing a NO_PROXY pattern to bypass the proxy.
refmap.gentoo: https://bugs.gentoo.org/951230
Labels: advisory, security
Proposed additive update for action disc-9bcab5916407ae05ea57 (issue #64)
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): Go proxy matching could improperly treat an IPv6 zone ID as a hostname component, allowing a NO_PROXY pattern to bypass the proxy.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Automated Flatcar security-triage review batch
32222485591, part 4 of 22.Run metadata
flatcar/security-triageflatcar/security-triagec90928f96af109865771b8b7539bf11c4d2f2ba4Summary
This part contains 21 decision group(s).
Whole batch: 531 decision group(s) across 22 part(s).
How to use this review
Decision groups
Group 70: libpcap (discovery, source: gentoo)
https://bugs.gentoo.org/939952Choose at most one (leave all unchecked to take no action for this group):
Group 71: cups (discovery, source: gentoo)
https://bugs.gentoo.org/940316Choose at most one (leave all unchecked to take no action for this group):
Group 72: net-analyzer/wireshark (discovery, source: gentoo)
https://bugs.gentoo.org/941560Choose at most one (leave all unchecked to take no action for this group):
Group 73: unbound (discovery, source: gentoo)
https://bugs.gentoo.org/941857Exact proposed issue for action
disc-6925b78930a8ea754a64Title:
update: unboundLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 74: python (discovery, source: gentoo)
https://bugs.gentoo.org/942077Exact proposed issue for action
disc-c4b3f0b6120def67f0c9Title:
update: pythonLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 75: podman (discovery, source: gentoo)
https://bugs.gentoo.org/942556Choose at most one (leave all unchecked to take no action for this group):
Group 76: 7zip (discovery, source: gentoo)
https://bugs.gentoo.org/945395Choose at most one (leave all unchecked to take no action for this group):
Group 77: curl (discovery, source: gentoo)
https://bugs.gentoo.org/946291Exact proposed issue for action
disc-3db38879d376bf88dafeTitle:
update: curlLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 78: asterisk (discovery, source: gentoo)
https://bugs.gentoo.org/947790Choose at most one (leave all unchecked to take no action for this group):
Group 79: vim (discovery, source: gentoo)
https://bugs.gentoo.org/947924Proposed additive update for action
disc-95c4c8024737c971070b(issue #153)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 80: dev-lang/go (discovery, source: gentoo)
https://bugs.gentoo.org/948232Exact proposed issue for action
disc-6149e8906119d25ccf66Title:
update: dev-lang/goLabels: advisory, security
Proposed additive update for action
disc-4206141b65623d471353(issue #64)This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 81: openssl (discovery, source: gentoo)
https://bugs.gentoo.org/948515Choose at most one (leave all unchecked to take no action for this group):
Group 82: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin (discovery, source: gentoo)
https://bugs.gentoo.org/948666Choose at most one (leave all unchecked to take no action for this group):
Group 83: net-dns/bind (discovery, source: gentoo)
https://bugs.gentoo.org/949125Proposed additive update for action
disc-915e12c0bd1a6f59d732(issue #61)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 84: net-misc/curl (discovery, source: gentoo)
https://bugs.gentoo.org/949330Exact proposed issue for action
disc-c49d92d7003186c333c8Title:
update: net-misc/curlLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 85: curl (discovery, source: gentoo)
https://bugs.gentoo.org/949342Choose at most one (leave all unchecked to take no action for this group):
Group 86: dev-lang/go (discovery, source: gentoo)
https://bugs.gentoo.org/949405Exact proposed issue for action
disc-776a79d63c4851103e98Title:
update: dev-lang/goLabels: advisory, security
Proposed additive update for action
disc-a10b67cebf4b5d27cb38(issue #64)This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 87: dev-ruby/net-imap (discovery, source: gentoo)
https://bugs.gentoo.org/949413Choose at most one (leave all unchecked to take no action for this group):
Group 88: dev-libs/libtasn1 (discovery, source: gentoo)
https://bugs.gentoo.org/949497Choose at most one (leave all unchecked to take no action for this group):
Group 89: openssl (discovery, source: gentoo)
https://bugs.gentoo.org/949620Choose at most one (leave all unchecked to take no action for this group):
Group 90: dev-lang/go (discovery, source: gentoo)
https://bugs.gentoo.org/951230Exact proposed issue for action
disc-169d4e3496ca398a4f54Title:
update: dev-lang/goLabels: advisory, security
Proposed additive update for action
disc-9bcab5916407ae05ea57(issue #64)This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.