[security][CVE-2026-53613] util-linux in redis runtime image #161
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
New unaddressed high-severity CVE detected in a deployed runtime image used by this repo.
Counters for this run:
unaddressed critical CVEs: 3unaddressed medium/low CVEs: 73unaddressed total CVEs: 89Finding
util-linuxin the deployedredis:7.2runtime imagedeployment/docker/docker-compose.ymlpinsredis:7.2redis:7.2:bsdutils,libblkid1,libmount1,libsmartcols1,libuuid1,mount,util-linux,util-linux-extraat2.38.1-5+deb12u3Project impact
This is a runtime/deployment finding, not a dev-only dependency issue. Islandflow ships Redis directly through
deployment/docker/docker-compose.yml, so the deployed Redis image currently inherits the vulnerableutil-linuxmount code. The advisory describes a local privilege-escalation path in the SUIDmountbinary via a TOCTOU race on the mount target path. Practical exploitability depends on container/runtime conditions such as allowing the vulnerable mount workflow, but the vulnerable code is present in a shipped image today.Recommended remediation
redis:7.2to a tag or digest that includes patchedutil-linuxpackagesCVE-2026-53613is goneValidation used in triage
trivy fsagainst the repo dependency/runtime surfacetrivy imageagainstredis:7.2,oven/bun:1.3.11,nats:2.10, andclickhouse/clickhouse-server:23.8Source links