[security][CVE-2026-78408] util-linux in Bun and Redis runtime images #169

Open
opened 2026-09-16 00:47:07 +00:00 by dirtydishes · 0 comments
Owner

"## Finding\n\n- CVE: CVE-2026-78408\n- Component: util-linux family (bsdutils, libmount1, and related packages)\n- In-repo runtime versions: oven/bun:1.3.11 (Debian 13.4, util-linux 2.41-5) and redis:7.2 (Debian 12.15, util-linux 2.38.1-5+deb12u3)\n- Severity: High, Red Hat CVSS 3.1 7.9\n\n## Project impact\n\nA local attacker who can invoke nsenter may gain root cgroup migration authority. Container privilege and namespace access determine practical exposure.\n\n## Remediation\n\nMove both base images to tags or digests that include the util-linux fix, then rescan the exact pulled digests. Avoid privileged containers and host namespace access until then.\n\n## Sources\n\n- https://nvd.nist.gov/vuln/detail/CVE-2026-78408\n- https://www.cve.org/CVERecord?id=CVE-2026-78408\n\n## Current automation counters\n\n- unaddressed critical CVEs: 2\n- unaddressed medium/low CVEs: 86\n- unaddressed total CVEs: 102\n"

"## Finding\n\n- CVE: `CVE-2026-78408`\n- Component: util-linux family (`bsdutils`, `libmount1`, and related packages)\n- In-repo runtime versions: `oven/bun:1.3.11` (Debian 13.4, util-linux `2.41-5`) and `redis:7.2` (Debian 12.15, util-linux `2.38.1-5+deb12u3`)\n- Severity: High, Red Hat CVSS 3.1 `7.9`\n\n## Project impact\n\nA local attacker who can invoke nsenter may gain root cgroup migration authority. Container privilege and namespace access determine practical exposure.\n\n## Remediation\n\nMove both base images to tags or digests that include the util-linux fix, then rescan the exact pulled digests. Avoid privileged containers and host namespace access until then.\n\n## Sources\n\n- https://nvd.nist.gov/vuln/detail/CVE-2026-78408\n- https://www.cve.org/CVERecord?id=CVE-2026-78408\n\n## Current automation counters\n\n- unaddressed critical CVEs: 2\n- unaddressed medium/low CVEs: 86\n- unaddressed total CVEs: 102\n"
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#169
No description provided.