Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Commit 5bde25d

Browse files
authored
falco-no-driver: update advisory (#27843)
Update advisory for CVE-2025-66506 falco-no-driver itself does not contain any code that is vulnerable to this CVE; however it pulls in libcontainer plugin from https://github.com/falcosecurity/plugins/tree/main/plugins/container which is vulnerable. The upstream maintainers will need to update to a new version of >= github.com/sigstore/fulcio and pull that in to fix the CVE. See also falcosecurity/plugins#1056 Signed-off-by: David Negreira <david.negreira@chainguard.dev>
1 parent f2af1cc commit 5bde25d

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

falco-no-driver.advisories.yaml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -145,6 +145,13 @@ advisories:
145145
componentType: go-module
146146
componentLocation: /usr/share/falco/plugins/libcontainer.so
147147
scanner: grype
148+
- timestamp: 2025-12-10T14:58:23Z
149+
type: pending-upstream-fix
150+
data:
151+
note: |
152+
falco-no-driver itself does not contain any code that is vulnerable to this CVE; however it pulls in libcontainer plugin from https://github.com/falcosecurity/plugins/tree/main/plugins/container which is vulnerable.
153+
The upstream maintainers will need to update to a new version of >= github.com/sigstore/fulcio and pull that in to fix the CVE.
154+
See also https://github.com/falcosecurity/plugins/issues/1056
148155
149156
- id: CGA-6rcj-3749-p5hw
150157
aliases:

0 commit comments

Comments
 (0)