Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix CVE-2024-33599 #33969

Closed
jpmca12 opened this issue May 6, 2024 · 3 comments
Closed

Fix CVE-2024-33599 #33969

jpmca12 opened this issue May 6, 2024 · 3 comments
Labels
bug triage Issue requires triage

Comments

@jpmca12
Copy link

jpmca12 commented May 6, 2024

Black Duck Binary Analysis reporting vulnerability CVE-2024-33599 on glibc 2.36-9+deb12u4, fix is available in 2.36-9+deb12u7.

Envoy version: envoy-distroless:v1.29.4

From this line https://github.com/envoyproxy/envoy/blob/v1.29.4/ci/Dockerfile-envoy#L61

cosign download attestation gcr.io/distroless/base-nossl-debian12:nonroot@sha256:0cf184cfdb9ac2878822b15b8917fae5d42fba26da654cd75ab3ed34add0737f | jq -rcs '.[0].payload' | base64 -d

found the glibc version used is 2.36-9+deb12u4

Looking here https://security-tracker.debian.org/tracker/CVE-2024-33599 found that the version 2.36-9+deb12u4 is vulnerable and fix is provided in 2.36-9+deb12u7.

can someone help fixing this. Let me know if I am missing anything. thanks.

cc: @phlax

@jpmca12 jpmca12 added bug triage Issue requires triage labels May 6, 2024
@phlax
Copy link
Member

phlax commented May 6, 2024

latest distroless image was updated here ba63c41 and picked to all branches

we dont generally cut releases for container fixes, and im struggling to find any information about this CVE

i generally update the ubuntu images close to when we are going to cut a release, but i will probably update these shortly

i think we can close this - we keep our branches up-to-date with what is available - in the distroless case this is done by dependabot

generally i do the backporting to ensure the supported branches are also up to date, but would appreciate any help with that

@phlax phlax closed this as completed May 6, 2024
@jpmca12
Copy link
Author

jpmca12 commented May 8, 2024

Thanks @phlax

Wondering when the fix would be available here https://hub.docker.com/r/envoyproxy/envoy-distroless/tags?page=1&page_size=&ordering=&name=v1.29 ?

Thanks

@phlax
Copy link
Member

phlax commented May 9, 2024

no fixed date as yet, but most likely in around a month

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug triage Issue requires triage
Projects
None yet
Development

No branches or pull requests

2 participants