Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Commit 4adb815

Browse files
OddBlokednegreira
andauthored
k3s-1.32,k3s-1.33: mark CVE-2025-67499 as pending-upstream-fix (#27845)
Co-authored-by: David Negreira <david.negreira@chainguard.dev>
1 parent 57015ca commit 4adb815

2 files changed

Lines changed: 8 additions & 0 deletions

File tree

k3s-1.32.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -153,6 +153,10 @@ advisories:
153153
componentType: go-module
154154
componentLocation: /usr/bin/cni
155155
scanner: grype
156+
- timestamp: 2025-12-10T16:21:00Z
157+
type: pending-upstream-fix
158+
data:
159+
note: k3s builds from a fork of containernetworking/plugins (https://github.com/rancher/plugins) and have not yet released a fixed version in their fork.
156160

157161
- id: CGA-55fv-m3qp-xh5q
158162
aliases:

k3s-1.33.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -117,6 +117,10 @@ advisories:
117117
componentType: go-module
118118
componentLocation: /usr/bin/cni
119119
scanner: grype
120+
- timestamp: 2025-12-10T16:21:00Z
121+
type: pending-upstream-fix
122+
data:
123+
note: k3s builds from a fork of containernetworking/plugins (https://github.com/rancher/plugins) and have not yet released a fixed version in their fork.
120124

121125
- id: CGA-6rh4-p5rc-q7f6
122126
aliases:

0 commit comments

Comments
 (0)