|
2 | 2 | "@context": "https://openvex.dev/ns/v0.2.0", |
3 | 3 | "@id": "https://github.com/StackVista/vexhub/pkg/oci/stackstate-k8s-agent/CVE-2026-6100", |
4 | 4 | "author": "SUSE Observability Security Team", |
5 | | - "version": 1, |
| 5 | + "version": 2, |
6 | 6 | "statements": [ |
7 | 7 | { |
8 | 8 | "vulnerability": { |
|
825 | 825 | "impact_statement": "CVE-2026-4360 affects tarfile.extract() handling of hardlinks. The sole shipped runtime extraction path iterates archive members, accepts only a member for which TarInfo.isfile() is true, renames the selected regular file to the fixed basename bpftool, and extracts only that member. Tar hardlinks have LNKTYPE and do not satisfy isfile(), so the vulnerable hardlink branch cannot be reached. Other repository extraction calls are build or test tooling and are not part of the agent runtime image.", |
826 | 826 | "action_statement": "Upgrade the embedded CPython runtime when a compatible 3.13.x patch release fixes CVE-2026-4360, then retire this statement. Re-review if shipped agent code adds another tar extraction path or permits hardlink members.", |
827 | 827 | "timestamp": "2026-07-20T07:19:56Z" |
| 828 | + }, |
| 829 | + { |
| 830 | + "vulnerability": { |
| 831 | + "name": "CVE-2026-50195", |
| 832 | + "aliases": [ |
| 833 | + "GHSA-cvxm-645q-p574" |
| 834 | + ] |
| 835 | + }, |
| 836 | + "products": [ |
| 837 | + { |
| 838 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=quay.io/stackstate/stackstate-k8s-agent", |
| 839 | + "subcomponents": [ |
| 840 | + { |
| 841 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 842 | + } |
| 843 | + ] |
| 844 | + }, |
| 845 | + { |
| 846 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=registry.rancher.com/suse-observability/stackstate-k8s-agent", |
| 847 | + "subcomponents": [ |
| 848 | + { |
| 849 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 850 | + } |
| 851 | + ] |
| 852 | + }, |
| 853 | + { |
| 854 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=registry.suse.com/suse-observability/stackstate-k8s-agent", |
| 855 | + "subcomponents": [ |
| 856 | + { |
| 857 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 858 | + } |
| 859 | + ] |
| 860 | + }, |
| 861 | + { |
| 862 | + "@id": "pkg:oci/stackstate-k8s-agent", |
| 863 | + "subcomponents": [ |
| 864 | + { |
| 865 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 866 | + } |
| 867 | + ] |
| 868 | + } |
| 869 | + ], |
| 870 | + "status": "not_affected", |
| 871 | + "status_notes": "Reviewed quay.io/stackstate/stackstate-k8s-agent:3ce0270e and source commit 3ce0270ebe on 2026-07-21. Grype 0.112.0 reports the advisory against github.com/containerd/containerd v1.7.33 in /opt/stackstate-agent/bin/agent/agent, but the upstream affected package is the distinct github.com/containerd/containerd/v2 module.", |
| 872 | + "justification": "vulnerable_code_not_present", |
| 873 | + "impact_statement": "CVE-2026-50195 affects only github.com/containerd/containerd/v2 versions in the 2.1, 2.2, and 2.3 release lines. The agent binary links github.com/containerd/containerd v1.7.33, whose Go module path does not contain the /v2 major-version suffix. Go major versions two and later use distinct module paths, and the affected /v2 component is not linked into this binary. The Grype finding results from matching the /v2 advisory to the major-v1 module after module-path normalization.", |
| 874 | + "action_statement": "Retire this statement when scanner matching no longer maps github.com/containerd/containerd/v2 advisories to the major-v1 module. Re-review if the agent starts linking github.com/containerd/containerd/v2 in an affected release line.", |
| 875 | + "timestamp": "2026-07-21T11:16:37Z" |
| 876 | + }, |
| 877 | + { |
| 878 | + "vulnerability": { |
| 879 | + "name": "CVE-2026-53492", |
| 880 | + "aliases": [ |
| 881 | + "GHSA-33vj-92qq-66hc" |
| 882 | + ] |
| 883 | + }, |
| 884 | + "products": [ |
| 885 | + { |
| 886 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=quay.io/stackstate/stackstate-k8s-agent", |
| 887 | + "subcomponents": [ |
| 888 | + { |
| 889 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 890 | + } |
| 891 | + ] |
| 892 | + }, |
| 893 | + { |
| 894 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=registry.rancher.com/suse-observability/stackstate-k8s-agent", |
| 895 | + "subcomponents": [ |
| 896 | + { |
| 897 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 898 | + } |
| 899 | + ] |
| 900 | + }, |
| 901 | + { |
| 902 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=registry.suse.com/suse-observability/stackstate-k8s-agent", |
| 903 | + "subcomponents": [ |
| 904 | + { |
| 905 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 906 | + } |
| 907 | + ] |
| 908 | + }, |
| 909 | + { |
| 910 | + "@id": "pkg:oci/stackstate-k8s-agent", |
| 911 | + "subcomponents": [ |
| 912 | + { |
| 913 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 914 | + } |
| 915 | + ] |
| 916 | + } |
| 917 | + ], |
| 918 | + "status": "not_affected", |
| 919 | + "status_notes": "Reviewed quay.io/stackstate/stackstate-k8s-agent:3ce0270e and source commit 3ce0270ebe on 2026-07-21. Grype 0.112.0 reports the advisory against github.com/containerd/containerd v1.7.33 in /opt/stackstate-agent/bin/agent/agent, but the upstream affected package is the distinct github.com/containerd/containerd/v2 module.", |
| 920 | + "justification": "vulnerable_code_not_present", |
| 921 | + "impact_statement": "CVE-2026-53492 affects only github.com/containerd/containerd/v2 versions in the 2.1, 2.2, and 2.3 release lines. The agent binary links github.com/containerd/containerd v1.7.33, whose Go module path does not contain the /v2 major-version suffix. Go major versions two and later use distinct module paths, and the affected /v2 component is not linked into this binary. The Grype finding results from matching the /v2 advisory to the major-v1 module after module-path normalization.", |
| 922 | + "action_statement": "Retire this statement when scanner matching no longer maps github.com/containerd/containerd/v2 advisories to the major-v1 module. Re-review if the agent starts linking github.com/containerd/containerd/v2 in an affected release line.", |
| 923 | + "timestamp": "2026-07-21T11:16:37Z" |
| 924 | + }, |
| 925 | + { |
| 926 | + "vulnerability": { |
| 927 | + "name": "CVE-2026-53489", |
| 928 | + "aliases": [ |
| 929 | + "GHSA-rgh6-rfwx-v388" |
| 930 | + ] |
| 931 | + }, |
| 932 | + "products": [ |
| 933 | + { |
| 934 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=quay.io/stackstate/stackstate-k8s-agent", |
| 935 | + "subcomponents": [ |
| 936 | + { |
| 937 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 938 | + } |
| 939 | + ] |
| 940 | + }, |
| 941 | + { |
| 942 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=registry.rancher.com/suse-observability/stackstate-k8s-agent", |
| 943 | + "subcomponents": [ |
| 944 | + { |
| 945 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 946 | + } |
| 947 | + ] |
| 948 | + }, |
| 949 | + { |
| 950 | + "@id": "pkg:oci/stackstate-k8s-agent?repository_url=registry.suse.com/suse-observability/stackstate-k8s-agent", |
| 951 | + "subcomponents": [ |
| 952 | + { |
| 953 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 954 | + } |
| 955 | + ] |
| 956 | + }, |
| 957 | + { |
| 958 | + "@id": "pkg:oci/stackstate-k8s-agent", |
| 959 | + "subcomponents": [ |
| 960 | + { |
| 961 | + "@id": "pkg:golang/github.com/containerd/[email protected]" |
| 962 | + } |
| 963 | + ] |
| 964 | + } |
| 965 | + ], |
| 966 | + "status": "not_affected", |
| 967 | + "status_notes": "Reviewed quay.io/stackstate/stackstate-k8s-agent:3ce0270e and source commit 3ce0270ebe on 2026-07-21. Grype 0.112.0 reports the advisory against github.com/containerd/containerd v1.7.33 in /opt/stackstate-agent/bin/agent/agent, but the upstream affected package is the distinct github.com/containerd/containerd/v2 module.", |
| 968 | + "justification": "vulnerable_code_not_present", |
| 969 | + "impact_statement": "CVE-2026-53489 affects only github.com/containerd/containerd/v2 versions in the 2.1, 2.2, and 2.3 release lines. The agent binary links github.com/containerd/containerd v1.7.33, whose Go module path does not contain the /v2 major-version suffix. Go major versions two and later use distinct module paths, and the affected /v2 component is not linked into this binary. The Grype finding results from matching the /v2 advisory to the major-v1 module after module-path normalization.", |
| 970 | + "action_statement": "Retire this statement when scanner matching no longer maps github.com/containerd/containerd/v2 advisories to the major-v1 module. Re-review if the agent starts linking github.com/containerd/containerd/v2 in an affected release line.", |
| 971 | + "timestamp": "2026-07-21T11:16:37Z" |
828 | 972 | } |
829 | 973 | ], |
830 | | - "timestamp": "2026-07-20T07:19:56Z" |
| 974 | + "timestamp": "2026-07-21T11:16:37Z" |
831 | 975 | } |
0 commit comments