[security][CVE-2026-54369] libacl1 in runtime base images #159

Open
opened 2026-08-16 14:17:12 +00:00 by dirtydishes · 0 comments
Owner

New active High CVE found in the deployed runtime base images during the August 16, 2026 CVE triage run.

  • CVE: CVE-2026-54369
  • Severity: High (CVSS 3.x 7.1 in Trivy vendor data)
  • Affected component: libacl1
  • In-repo/runtime versions:
    • oven/bun:1.3.11 -> libacl1 2.3.2-2+b1 (Debian 13.4 / trixie)
    • redis:7.2 -> libacl1 2.3.1-3 (Debian 12.15 / bookworm)
  • Project impact: the runtime containers inherit a symlink-traversal flaw in libacl pathname-based ACL helpers. Because the Docker runtime images in this repo do not set a non-root USER, a foothold inside one of these containers makes local privilege escalation or ACL tampering more meaningful than a dormant library issue.
  • Remediation guidance: move to runtime image rebuilds that carry acl 2.4.0 or the vendor-patched distro package once Bun/Redis publish them; until then, prefer hardened non-root containers and rescan image digests before rollout.

Sources:

Current counters for this run:

  • unaddressed critical CVEs: 4
  • unaddressed medium/low CVEs: 71
  • unaddressed total CVEs: 87
New active High CVE found in the deployed runtime base images during the August 16, 2026 CVE triage run. - CVE: CVE-2026-54369 - Severity: High (CVSS 3.x 7.1 in Trivy vendor data) - Affected component: `libacl1` - In-repo/runtime versions: - `oven/bun:1.3.11` -> `libacl1 2.3.2-2+b1` (Debian 13.4 / trixie) - `redis:7.2` -> `libacl1 2.3.1-3` (Debian 12.15 / bookworm) - Project impact: the runtime containers inherit a symlink-traversal flaw in libacl pathname-based ACL helpers. Because the Docker runtime images in this repo do not set a non-root `USER`, a foothold inside one of these containers makes local privilege escalation or ACL tampering more meaningful than a dormant library issue. - Remediation guidance: move to runtime image rebuilds that carry `acl` 2.4.0 or the vendor-patched distro package once Bun/Redis publish them; until then, prefer hardened non-root containers and rescan image digests before rollout. Sources: - https://www.cve.org/CVERecord?id=CVE-2026-54369 - https://nvd.nist.gov/vuln/detail/CVE-2026-54369 - https://security-tracker.debian.org/tracker/CVE-2026-54369 - https://security-tracker.debian.org/tracker/source-package/acl Current counters for this run: - unaddressed critical CVEs: 4 - unaddressed medium/low CVEs: 71 - unaddressed total CVEs: 87
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#159
No description provided.