[Q&A] CVE-2026-13221 (perl v5.40.1) in fluentd:v1.19.3-debian-1.0 #5485
What is a problem?contains the CVE ID. But not the CVE-2026-13221 is not on the list. It seems it was, but then removed. Any idea? Secondly, going into the image itself, running perl -v, i get Considering that https://nvd.nist.gov/vuln/detail/cve-2026-13221 any perl up to (including) 5.43.9 is affected, I would expect cve-2026-13221 being part of the list. Describe the configuration of Fluentddownload into docker images, run it, and attach to process. Describe the logs of FluentdNo response Environment- Fluentd version:
$ fluentd --version
fluentd 1.19.3
- TD Agent version:
- Fluent Package version:
- Docker image (tag): fluentd:v1.19.3-debian-1.0
- Operating system:
PRETTY_NAME="Debian GNU/Linux 13 (trixie)"
NAME="Debian GNU/Linux"
VERSION_ID="13"
VERSION="13 (trixie)"
VERSION_CODENAME=trixie
DEBIAN_VERSION_FULL=13.6
ID=debian
HOME_URL="https://www.debian.org/"
SUPPORT_URL="https://www.debian.org/support"
BUG_REPORT_URL="https://bugs.debian.org/"
- Kernel version: |
Replies: 1 comment
|
You mention about https://hub.docker.com/_/fluentd/, not https://hub.docker.com/r/fluent/fluentd. That image was derived from https://github.com/docker-library/official-images. FYI: CVE-2026-13321 will be fixed in next Debian 13.7 point release (around Sep 12?), so we will update https://hub.docker.com/r/fluent/fluentd images later. trixie-pu: package perl/5.40.1-6+deb13u1 |
You mention about https://hub.docker.com/_/fluentd/, not https://hub.docker.com/r/fluent/fluentd.
(Thus it's out of scope from fluentd maintainer side)
That image was derived from https://github.com/docker-library/official-images.
I don't know how they are built nor scanned vulnerability. so it might be better to ask there.
FYI: CVE-2026-13321 will be fixed in next Debian 13.7 point release (around Sep 12?), so we will update https://hub.docker.com/r/fluent/fluentd images later.
trixie-pu: package perl/5.40.1-6+deb13u1
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146369