Skip to content

Monthly GLSA metadata 2025-07-01 #3064

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

flatcar-infra
Copy link

Updated GLSA metadata

@dongsupark
Copy link
Member

dongsupark commented Jul 1, 2025

This PR is blocked by pam update, 202505-01, which points to CVE-2024-10041, only CVSS 4.7, and CVE-2024-22365, CVSS 5.5. Both are already handled by an open issue flatcar/Flatcar#1349.
I am not sure if the former issue would be a valid issue for Flatcar, because the possible impact would be password leaks. At least not that red flag to be blocked by GLSA. On the other hand, the latter issue seems to be a valid issue for Flatcar.
In any case, I would not call any of them a GLSA issue.

If GLSA would try to address the 2 other issues, CVE-2024-10963, CVSS 7.4, CVE-2025-6020, CVSS 7.8, then I could understand. However, that is also not the case. So I do not quite understand reasoning from upstream.

Anyway, as discussed in flatcar/Flatcar#1349, we are going to anyway update pam soon.

Copy link

github-actions bot commented Jul 1, 2025

Build action triggered: https://github.com/flatcar/scripts/actions/runs/15996551767

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants