[security][CVE-2026-53613] util-linux in redis runtime image #161

Open
opened 2026-08-20 13:19:27 +00:00 by dirtydishes · 0 comments
Owner

Summary

New unaddressed high-severity CVE detected in a deployed runtime image used by this repo.

Counters for this run:

  • unaddressed critical CVEs: 3
  • unaddressed medium/low CVEs: 73
  • unaddressed total CVEs: 89

Finding

  • CVE: CVE-2026-53613
  • Affected component: util-linux in the deployed redis:7.2 runtime image
  • In-repo usage:
    • deployment/docker/docker-compose.yml pins redis:7.2
  • Vulnerable packages reported by the current scan:
    • redis:7.2: bsdutils, libblkid1, libmount1, libsmartcols1, libuuid1, mount, util-linux, util-linux-extra at 2.38.1-5+deb12u3
  • Severity: High
  • Score: GitHub advisory CVSS 7.0 (High); Ubuntu currently labels it Medium with CVSS 6.5, so vendor severity differs

Project impact

This is a runtime/deployment finding, not a dev-only dependency issue. Islandflow ships Redis directly through deployment/docker/docker-compose.yml, so the deployed Redis image currently inherits the vulnerable util-linux mount code. The advisory describes a local privilege-escalation path in the SUID mount binary via a TOCTOU race on the mount target path. Practical exploitability depends on container/runtime conditions such as allowing the vulnerable mount workflow, but the vulnerable code is present in a shipped image today.

  • Refresh redis:7.2 to a tag or digest that includes patched util-linux packages
  • Prefer an exact image digest once upstream republishes with the fixed Debian package set
  • Re-scan the refreshed Redis image to confirm CVE-2026-53613 is gone

Validation used in triage

  • trivy fs against the repo dependency/runtime surface
  • trivy image against redis:7.2, oven/bun:1.3.11, nats:2.10, and clickhouse/clickhouse-server:23.8
  • repo inspection of deployment Dockerfiles and compose definitions
  • duplicate check against existing Forgejo issues, PRs, automation memory, and local git history
## Summary New unaddressed high-severity CVE detected in a deployed runtime image used by this repo. Counters for this run: - `unaddressed critical CVEs: 3` - `unaddressed medium/low CVEs: 73` - `unaddressed total CVEs: 89` ## Finding - CVE: [CVE-2026-53613](https://nvd.nist.gov/vuln/detail/CVE-2026-53613) - Affected component: `util-linux` in the deployed `redis:7.2` runtime image - In-repo usage: - `deployment/docker/docker-compose.yml` pins `redis:7.2` - Vulnerable packages reported by the current scan: - `redis:7.2`: `bsdutils`, `libblkid1`, `libmount1`, `libsmartcols1`, `libuuid1`, `mount`, `util-linux`, `util-linux-extra` at `2.38.1-5+deb12u3` - Severity: High - Score: GitHub advisory CVSS 7.0 (High); Ubuntu currently labels it Medium with CVSS 6.5, so vendor severity differs ## Project impact This is a runtime/deployment finding, not a dev-only dependency issue. Islandflow ships Redis directly through `deployment/docker/docker-compose.yml`, so the deployed Redis image currently inherits the vulnerable `util-linux` mount code. The advisory describes a local privilege-escalation path in the SUID `mount` binary via a TOCTOU race on the mount target path. Practical exploitability depends on container/runtime conditions such as allowing the vulnerable mount workflow, but the vulnerable code is present in a shipped image today. ## Recommended remediation - Refresh `redis:7.2` to a tag or digest that includes patched `util-linux` packages - Prefer an exact image digest once upstream republishes with the fixed Debian package set - Re-scan the refreshed Redis image to confirm `CVE-2026-53613` is gone ## Validation used in triage - `trivy fs` against the repo dependency/runtime surface - `trivy image` against `redis:7.2`, `oven/bun:1.3.11`, `nats:2.10`, and `clickhouse/clickhouse-server:23.8` - repo inspection of deployment Dockerfiles and compose definitions - duplicate check against existing Forgejo issues, PRs, automation memory, and local git history ## Source links - https://nvd.nist.gov/vuln/detail/CVE-2026-53613 - https://security-tracker.debian.org/tracker/CVE-2026-53613 - https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g - https://ubuntu.com/security/CVE-2026-53613
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#161
No description provided.