Skip to content

Conversation

@anabel-ksp
Copy link
Collaborator

This patch fixes security vulnerabilities in the Alpine Linux base image by upgrading vulnerable system packages in docker/sysds.Dockerfile.

Fixed CVEs (openssl):

  • CVE-2025-9230 (High): upgraded to 3.3.5-r0
  • CVE-2025-9231 (Medium): upgraded to 3.3.5-r0
  • CVE-2025-9232 (Medium): upgraded to 3.3.5-r0

Fixed CVEs (busybox):

Unfixable CVEs (no upstream patch available):

Also added exclusions in pom.xml for guava, jackson, and jetty transitive dependencies from Spark/Hadoop to use managed versions.

This patch fixes security vulnerabilities in the Alpine Linux base image
by upgrading vulnerable system packages in docker/sysds.Dockerfile.

Fixed CVEs (openssl):
- CVE-2025-9230 (High): upgraded to 3.3.5-r0
- CVE-2025-9231 (Medium): upgraded to 3.3.5-r0
- CVE-2025-9232 (Medium): upgraded to 3.3.5-r0

Fixed CVEs (busybox):
- CVE-2025-46394: upgraded from 1.36.1-r29 to 1.36.1-r31
- CVE-2024-58251: upgraded from 1.36.1-r29 to 1.36.1-r31

Unfixable CVEs (no upstream patch available):
- CVE-2025-60876 (busybox): Not Fixed by Alpine
- CVE-2026-22184 (zlib): Not Fixed by Alpine
- CVE-2025-62813 (lz4): Not Fixed by Alpine

Also added exclusions in pom.xml for guava, jackson, and jetty
transitive dependencies from Spark/Hadoop to use managed versions.
@qschnee qschnee merged commit a7d2391 into main Jan 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants