Skip to content

[vuln-scan] HIGH/CRITICAL findings in cds-dbt #486

Description

@github-actions

HIGH/CRITICAL vulnerabilities detected

  • Scanned target: ghcr.io/ronaldhensbergen/cds-dbt@sha256:bf9f563d65fe92b1ae4eb369100e6a8fa601d9df68cdd0b42b6c68d301bd25fc
  • Pipeline run: Image Security Scan

https://github.com/RonaldHensbergen/composable-data-stack/actions/runs/32550448352

  • SLA: HIGH and CRITICAL findings must be remediated by 2026-08-25 (see docs/image-scanning.md). Open a Renovate/dependency bump or a rebuild PR, or file an exception per docs/image-scanning.md.

Findings


Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬────────────┬─────────────────┐
│                                      Target                                      │    Type    │ Vulnerabilities │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ ghcr.io/ronaldhensbergen/cds-dbt@sha256:bf9f563d65fe92b1ae4eb369100e6a8fa601d9d- │   debian   │       27        │
│ f68cdd0b42b6c68d301bd25fc (debian 13.6)                                          │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/agate-1.9.1.dist-info/METADATA             │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/annotated_types-0.8.0.dist-info/METADATA   │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/attrs-26.1.0.dist-info/METADATA            │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/babel-2.18.0.dist-info/METADATA            │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/certifi-2026.7.22.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/charset_normalizer-3.5.1.dist-info/METADA- │ python-pkg │        0        │
│ TA                                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/click-8.4.2.dist-info/METADATA             │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/colorama-0.4.6.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/daff-1.4.2.dist-info/METADATA              │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dbt_adapters-1.24.5.dist-info/METADATA     │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dbt_common-1.39.0.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dbt_core-1.12.2.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dbt_core_experimental_parser-2.0.0b2.dist- │ python-pkg │        0        │
│ -info/METADATA                                                                   │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dbt_extractor-0.6.0.dist-info/METADATA     │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dbt_postgres-1.11.0.dist-info/METADATA     │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dbt_protos-1.0.565.dist-info/METADATA      │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/deepdiff-8.6.2.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/idna-3.19.dist-info/METADATA               │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/importlib_metadata-9.0.0.dist-info/METADA- │ python-pkg │        0        │
│ TA                                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/isodate-0.7.2.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/jinja2-3.1.6.dist-info/METADATA            │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/jsonschema-4.26.0.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/jsonschema_specifications-2025.9.1.dist-i- │ python-pkg │        0        │
│ nfo/METADATA                                                                     │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/leather-0.4.1.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/markupsafe-3.0.3.dist-info/METADATA        │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/mashumaro-3.17.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/metricflow-0.212.0.dist-info/METADATA      │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/more_itertools-10.8.0.dist-info/METADATA   │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/msgpack-1.2.1.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/networkx-3.6.1.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/opentelemetry_api-1.44.0.dist-info/METADA- │ python-pkg │        0        │
│ TA                                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/orderly_set-5.5.0.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/packaging-26.3.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/parsedatetime-2.6.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pathspec-1.0.4.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/protobuf-6.33.6.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/psycopg2_binary-2.9.12.dist-info/METADATA  │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pydantic-2.13.4.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pydantic_core-2.46.4.dist-info/METADATA    │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/python_dateutil-2.9.0.post0.dist-info/MET- │ python-pkg │        0        │
│ ADATA                                                                            │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/python_dotenv-1.2.3.dist-info/METADATA     │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/python_slugify-8.0.4.dist-info/METADATA    │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pytimeparse-1.1.8.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pytz-2026.3.post1.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pyyaml-6.0.3.dist-info/METADATA            │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/rapidfuzz-3.14.5.dist-info/METADATA        │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/referencing-0.37.0.dist-info/METADATA      │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/requests-2.34.2.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/rpds_py-2026.6.3.dist-info/METADATA        │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/six-1.17.0.dist-info/METADATA              │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/snowplow_tracker-1.1.0.dist-info/METADATA  │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/sqlglot-30.17.0.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/sqlparse-0.5.5.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/tabulate-0.10.0.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/text_unidecode-1.3.dist-info/METADATA      │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/typing_extensions-4.16.0.dist-info/METADA- │ python-pkg │        0        │
│ TA                                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/typing_inspection-0.4.4.dist-info/METADATA │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/urllib3-2.7.0.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/zipp-4.1.0.dist-info/METADATA              │ python-pkg │        0        │
└──────────────────────────────────────────────────────────────────────────────────┴────────────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.74/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


ghcr.io/ronaldhensbergen/cds-dbt@sha256:bf9f563d65fe92b1ae4eb369100e6a8fa601d9df68cdd0b42b6c68d301bd25fc (debian 13.6)
======================================================================================================================
Total: 27 (HIGH: 27, CRITICAL: 0)

┌───────────────┬────────────────┬──────────┬────────┬─────────────────────────┬──────────────────┬────────────────────────────────────────────────────────────┐
│    Library    │ Vulnerability  │ Severity │ Status │    Installed Version    │  Fixed Version   │                           Title                            │
├───────────────┼────────────────┼──────────┼────────┼─────────────────────────┼──────────────────┼────────────────────────────────────────────────────────────┤
│ bsdutils      │ CVE-2026-53612 │ HIGH     │ fixed  │ 1:2.41-5                │ 2.41.5-0+deb13u1 │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        ├─────────────────────────┤                  ├────────────────────────────────────────────────────────────┤
│ libblkid1     │ CVE-2026-53612 │          │        │ 2.41-5                  │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ liblastlog2-2 │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ libmount1     │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ libsmartcols1 │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ libuuid1      │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        ├─────────────────────────┤                  ├────────────────────────────────────────────────────────────┤
│ login         │ CVE-2026-53612 │          │        │ 1:4.16.0-2+really2.41-5 │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        ├─────────────────────────┤                  ├────────────────────────────────────────────────────────────┤
│ mount         │ CVE-2026-53612 │          │        │ 2.41-5                  │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ util-linux    │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
└───────────────┴────────────────┴──────────┴────────┴─────────────────────────┴──────────────────┴────────────────────────────────────────────────────────────┘

Metadata

Metadata

Assignees

No one assigned

    Labels

    vuln-scanScheduled image scan found HIGH/CRITICAL vulnerabilities

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions