Skip to content

Fix of CVE-2025-9230 in Docker Image 1.71.1 #8899

@marcfischer

Description

@marcfischer

Hi there,

one of my customers is using the rclone docker image and can currently not import the container image in his environment due to security CVE scans. We tried it with the container Image 1.71.1 from Dockerhub (clone/rclone:1.71.1) and sysdig finds this critical Security issue:

--> CVE-2025-9230 (VulnDB Score 9.8):

Affected Packages and Versions

  • libssl3 3.5.1-r0 (-> fixed in 3.5.4-r0)
  • libcrypto3 3.5.1-r0 (-> fixed in 3.5.4-r0)

Would it be possible to update these packages in the next version?

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0 - CriticalPotential data loss, data corruption, or active security exploit (e.g., remote code execution).securityPotential security problem

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions