CVE-2025-4574 detected in earlier version #9520
Closed
hoerup
started this conversation in
False Detection
Replies: 3 comments
-
|
Please report it to GitHub. Guidance here. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Beta Was this translation helpful? Give feedback.
0 replies
-
|
github/advisory-database#6201 has been merged |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
CVE-2025-4574
Description
When scanning an alpine 3.22 base image with librav1e installed, trivy detects CVE-2025-4574 due to the rav1e library being build with crossbeam-channel rust crate v 0.5.11 BUT the vulnerability is first introduced in 0.5.12
https://bugzilla.redhat.com/show_bug.cgi?id=2358890
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Alpine
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions