Debian Bookworm CVE-2025-49794 detected in libxml2 2.9.14+dfsg-1.3~deb12u4 despite Debian's tracker reporting this version as fixed #9426
Closed
someone-stole-my-name
started this conversation in
False Detection
Replies: 1 comment 2 replies
-
|
Hello @someone-stole-my-name I created aquasecurity/vuln-list-update#372 Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
CVE-2025-49794
Description
Trivy is detecting CVE-2025-49794 in Bookworm derived images with versions of libxml2 marked as fixed in the Debian tracker, eg
2.9.14+dfsg-1.3~deb12u4.Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Debian Bookworm
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions