Skip to content

Addressing CVE in agent 7.73.0 #42871

@bruvio

Description

@bruvio

Hiya,
AWS Inspector (and grype) picked these vulnerabilities

stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-61723 High < 0.1% (23rd) < 0.1
stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-61725 High < 0.1% (23rd) < 0.1
stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-58186 Medium < 0.1% (17th) < 0.1
stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-61724 Medium < 0.1% (17th) < 0.1
stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-47912 Medium < 0.1% (16th) < 0.1
stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-58188 High < 0.1% (8th) < 0.1
stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-58189 Medium < 0.1% (12th) < 0.1
linux-pam 1.7.0-r4 apk CVE-2024-10041 Medium < 0.1% (8th) < 0.1
stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-58185 Medium < 0.1% (6th) < 0.1
stdlib go1.24.7 1.24.9, 1.25.3 go-module CVE-2025-58187 High < 0.1% (2nd) < 0.1
github.com/opencontainers/selinux v1.12.0 1.13.0 go-module GHSA-cgrx-mc8f-2prm High < 0.1% (0th) < 0.1
stdlib go1.24.7 1.24.8, 1.25.2 go-module CVE-2025-58183 Medium < 0.1% (2nd) < 0.1
github.com/containerd/containerd/v2 v2.1.4 2.1.5 go-module GHSA-m6hq-p25p-ffr2 Medium < 0.1% (1st) < 0.1
busybox 1.37.0-r19 apk CVE-2025-46394 Low < 0.1% (1st) < 0.1
busybox-binsh 1.37.0-r19 apk CVE-2025-46394 Low < 0.1% (1st) < 0.1
ssl_client 1.37.0-r19 apk CVE-2025-46394 Low < 0.1% (1st) < 0.1
busybox 1.37.0-r19 apk CVE-2024-58251 Low < 0.1% (3rd) < 0.1
busybox-binsh 1.37.0-r19 apk CVE-2024-58251 Low < 0.1% (3rd) < 0.1
ssl_client 1.37.0-r19 apk CVE-2024-58251 Low < 0.1% (3rd) < 0.1
github.com/containerd/containerd/v2 v2.1.4 2.1.5 go-module GHSA-pwhc-rpq9-4c8w High < 0.1% (0th) < 0.1

would it be possible to address them?

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions