You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The production SBOM confirms util-linux is shipped, and the open matching issue 70 does not include CVE-2025-14104 or Gentoo bug 967612. The shipped 2.41.4-r1 version is newer than the stated 2.41.3 fix, but the existing util-linux tracking issue should be updated with this CVE and reference.
Proposed additive update for action disc-10e48fe0ef686e837aa3 (issue #70)
Action Needed (only applied if currently TBD): TBD
Summary (only applied if currently TBD): Heap buffer overread in util-linux setpwnam() when processing 256-byte usernames, affecting SUID login-utils utilities that write to the password database.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2025-14104
- Add Gentoo aliases/CVEs: CVE-2025-14104
- Add upstream context: Heap buffer overread in util-linux setpwnam() when processing 256-byte usernames, affecting SUID login-utils utilities that write to the password database.
- Review Gentoo severity: minor
- Review Bugzilla description: """
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
"""
https://github.com/util-linux/util-linu...
- Review Bugzilla comment #2 by bacs at 2026-08-16T12:32:40Z: glsa^ with 971935
New Bugzilla comments in the processing window:
- Review Bugzilla comment #2 by bacs at 2026-08-16T12:32:40Z: glsa^ with 971935
Source: https://bugs.gentoo.org/967612
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Exact proposed issue for action disc-32990b2b63369914eceb
Title: update: dropbear
Name: dropbear
CVEs: CVE-2025-14282
CVSSs: n/a
Action Needed: update target
Summary: Dropbear server versions 2024.84 through 2025.88 contain a privilege-escalation vulnerability allowing authenticated users to run arbitrary programs as root, depending on other system programs; fixed in 2025.89.
refmap.gentoo: https://bugs.gentoo.org/967696
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
The production SBOM contains the exact GnuPG package, but at 2.5.20-r1, which is newer than the stated fixed version 2.5.16 and outside the affected range (<2.5.16).
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 132: app-crypt/age (discovery, source: gentoo)
The production SBOM contains net-libs/libpcap 1.10.6, while the reported affected range is below 1.10.6 and no existing Flatcar issue matches these CVEs.
Choose at most one (leave all unchecked to take no action for this group):
CVE-2026-1220 affects Chromium-based desktop web browsers, which are outside Flatcar's relevant server-package scope, and no production SBOM evidence shows that any affected browser is shipped.
Choose at most one (leave all unchecked to take no action for this group):
The production SBOM confirms glibc is shipped, and open issue #154 already tracks glibc. CVE-2025-15281 is not listed there and the Gentoo/sourceware references and affected-version context should be added; the shipped 2.43-r2 version is outside the reported affected range through 2.42.
Proposed additive update for action disc-7c296d4191b34fd2eca8 (issue #154)
Action Needed (only applied if currently TBD): TBD
Summary (only applied if currently TBD): glibc wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized pointers in we_wordv, potentially causing invalid-pointer dereference or process abort.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2025-15281
- Add Gentoo aliases/CVEs: CVE-2025-15281
- Add upstream context: glibc wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized pointers in we_wordv, potentially causing invalid-pointer dereference or process abort.
- Review Gentoo severity: normal
- Review upstream references: https://sourceware.org/bugzilla/show_bug.cgi?id=33814
- Review Bugzilla description: Low impact again.
"""
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
The implementation o...
- Review Bugzilla comment #1 by bacs at 2026-08-16T12:17:57Z: glsa^ with 968862
New Bugzilla comments in the processing window:
- Review Bugzilla comment #1 by bacs at 2026-08-16T12:17:57Z: glsa^ with 968862
Source: https://bugs.gentoo.org/969087
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
The open net-dns/bind issue is an exact package match but does not list CVE-2025-13878. Add the CVE, Gentoo/ISC references, affected and fixed version context, noting that the production SBOM version 9.20.23 is newer than the 9.20.18 fix.
Proposed additive update for action disc-18f16cfad6f582501ec2 (issue #61)
Action Needed (only applied if currently TBD): TBD
Summary (only applied if currently TBD): Malformed BRID/HHIT records can cause named to terminate unexpectedly; fixed in BIND 9.18.44, 9.20.18, and 9.21.17.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2025-13878
- Add Gentoo aliases/CVEs: CVE-2025-13878
- Add upstream context: Malformed BRID/HHIT records can cause named to terminate unexpectedly; fixed in BIND 9.18.44, 9.20.18, and 9.21.17.
- Review Gentoo severity: minor (source: https://kb.isc.org/docs/cve-2025-13878)
- Review upstream references: https://kb.isc.org/docs/cve-2025-13878
- Review Bugzilla description: CVE-2025-13878: Malformed BRID/HHIT records can cause named to terminate unexpectedly
Affected:
9.18.40 -> 9.18.43
9.20.13 -> 9.20.17
9.21.12 -> 9.21.16
Fixed in:
9.18.44
9.20.18
9.21.17
Reproducible: Always
Source: https://bugs.gentoo.org/969156
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
GIMP is a desktop graphics application, has no production SBOM match, and Gentoo explicitly states media-gfx/gimp is not in @system or its dependencies.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 140: www-client/chromium (discovery, source: gentoo)
CVE-2026-1504 affects Chromium-based desktop browser packages, which are outside Flatcar's server-focused package scope, and no production SBOM evidence shows that Flatcar ships them.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 141: tor (discovery, source: gentoo)
Source URL: https://bugs.gentoo.org/969415
CVEs / upstream IDs: TROVE-2025-016, TOR BUG 41180
Tor is not evidenced as shipped or used by Flatcar; there are no production SBOM matches, and the source explicitly states net-vpn/tor is not in Gentoo @system or dependencies.
Choose at most one (leave all unchecked to take no action for this group):
Exact proposed issue for action disc-4f5fd2cd4c7ed1250475
Title: update: nginx
Name: nginx
CVEs: CVE-2026-1642
CVSSs: 5.9, 8.2
Action Needed: update target
Summary: NGINX configured to proxy to upstream TLS servers may allow an upstream-side MITM attacker to inject plaintext data into proxied responses sent to clients.
refmap.gentoo: https://bugs.gentoo.org/969626
Labels: advisory, security, cvss/HIGH
Choose at most one (leave all unchecked to take no action for this group):
Create new advisory issue: update: nginx
No advisory action (ignore/defer)
Manual handling outside the pipeline
Group 144: net-misc/freerdp (discovery, source: gentoo)
FreeRDP has no production SBOM match or other evidence of being shipped or used by Flatcar; the Gentoo advisory alone does not establish Flatcar relevance.
Choose at most one (leave all unchecked to take no action for this group):
Wireshark is not evidenced in the Flatcar production SBOM or otherwise shown to be shipped or used by Flatcar; it is a network-analysis application outside the limited production package set.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 152: dev-python/django (discovery, source: gentoo)
The production SBOM confirms libxml2 is shipped, but at 2.15.3, which is newer than the affected range (<2.15.2) and includes the 2.15.2 fixes. No evidence shows an affected Flatcar version requiring an advisory.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 154: dev-lang/go (discovery, source: gentoo)
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): Go fixes URL parsing validation, html/template meta-refresh URL escaping, and FileInfo metadata escapes from Root; fixed in Go 1.25.8.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Automated Flatcar security-triage review batch
32222485591, part 7 of 22.Run metadata
flatcar/security-triageflatcar/security-triagec90928f96af109865771b8b7539bf11c4d2f2ba4Summary
This part contains 27 decision group(s).
Whole batch: 531 decision group(s) across 22 part(s).
How to use this review
Decision groups
Group 128: util-linux (discovery, source: gentoo)
https://bugs.gentoo.org/967612Proposed additive update for action
disc-10e48fe0ef686e837aa3(issue #70)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 129: dropbear (discovery, source: gentoo)
https://bugs.gentoo.org/967696Exact proposed issue for action
disc-32990b2b63369914ecebTitle:
update: dropbearLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 130: nginx (discovery, source: gentoo)
https://bugs.gentoo.org/967910Choose at most one (leave all unchecked to take no action for this group):
Group 131: gnupg (discovery, source: gentoo)
https://bugs.gentoo.org/968171Choose at most one (leave all unchecked to take no action for this group):
Group 132: app-crypt/age (discovery, source: gentoo)
https://bugs.gentoo.org/968204Choose at most one (leave all unchecked to take no action for this group):
Group 133: libpcap (discovery, source: gentoo)
https://bugs.gentoo.org/968315Choose at most one (leave all unchecked to take no action for this group):
Group 134: libtasn1 (discovery, source: gentoo)
https://bugs.gentoo.org/968531Choose at most one (leave all unchecked to take no action for this group):
Group 135: www-client/chromium (discovery, source: gentoo)
https://bugs.gentoo.org/969084Choose at most one (leave all unchecked to take no action for this group):
Group 136: glibc (discovery, source: gentoo)
https://bugs.gentoo.org/969087Proposed additive update for action
disc-7c296d4191b34fd2eca8(issue #154)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 137: net-dns/bind (discovery, source: gentoo)
https://bugs.gentoo.org/969156Proposed additive update for action
disc-18f16cfad6f582501ec2(issue #61)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 138: media-gfx/gimp (discovery, source: gentoo)
https://bugs.gentoo.org/969286Choose at most one (leave all unchecked to take no action for this group):
Group 139: gimp (discovery, source: gentoo)
https://bugs.gentoo.org/969287Choose at most one (leave all unchecked to take no action for this group):
Group 140: www-client/chromium (discovery, source: gentoo)
https://bugs.gentoo.org/969398Choose at most one (leave all unchecked to take no action for this group):
Group 141: tor (discovery, source: gentoo)
https://bugs.gentoo.org/969415Choose at most one (leave all unchecked to take no action for this group):
Group 142: curl (discovery, source: gentoo)
https://bugs.gentoo.org/969430Exact proposed issue for action
disc-be0167379b21b15eea84Title:
update: curlLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 143: nginx (discovery, source: gentoo)
https://bugs.gentoo.org/969626Exact proposed issue for action
disc-4f5fd2cd4c7ed1250475Title:
update: nginxLabels: advisory, security, cvss/HIGH
Choose at most one (leave all unchecked to take no action for this group):
Group 144: net-misc/freerdp (discovery, source: gentoo)
https://bugs.gentoo.org/969847Choose at most one (leave all unchecked to take no action for this group):
Group 145: yt-dlp (discovery, source: gentoo)
https://bugs.gentoo.org/970421Choose at most one (leave all unchecked to take no action for this group):
Group 146: net-p2p/freenet (discovery, source: gentoo)
https://bugs.gentoo.org/970477Choose at most one (leave all unchecked to take no action for this group):
Group 147: cups-filters (discovery, source: gentoo)
https://bugs.gentoo.org/970481Choose at most one (leave all unchecked to take no action for this group):
Group 148: net-print/cups (discovery, source: gentoo)
https://bugs.gentoo.org/970482Choose at most one (leave all unchecked to take no action for this group):
Group 149: www-client/firefox (discovery, source: gentoo)
https://bugs.gentoo.org/970560Choose at most one (leave all unchecked to take no action for this group):
Group 150: mail-client/thunderbird (discovery, source: gentoo)
https://bugs.gentoo.org/970561Choose at most one (leave all unchecked to take no action for this group):
Group 151: wireshark (discovery, source: gentoo)
https://bugs.gentoo.org/970622Choose at most one (leave all unchecked to take no action for this group):
Group 152: dev-python/django (discovery, source: gentoo)
https://bugs.gentoo.org/970871Choose at most one (leave all unchecked to take no action for this group):
Group 153: libxml2 (discovery, source: gentoo)
https://bugs.gentoo.org/970915Choose at most one (leave all unchecked to take no action for this group):
Group 154: dev-lang/go (discovery, source: gentoo)
https://bugs.gentoo.org/970944Exact proposed issue for action
disc-d7c9edc64ca70ee46d85Title:
update: dev-lang/goLabels: advisory, security
Proposed additive update for action
disc-2666dbea89a4c1d9ce25(issue #64)This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.