Skip to content

Trivy Image Scan is failing #6950

@arkodg

Description

@arkodg

Description:

Describe the issue.

https://github.com/envoyproxy/gateway/actions/runs/17681793112/job/50257417074

envoy-proxy/gateway-dev:4b1827909115e2cb509609f773ed58fbd3f47a5e (debian 12.11)
===============================================================================
Total: 2 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 1, CRITICAL: 0)

┌─────────┬───────────────┬──────────┬────────┬───────────────────┬─────────────────┬───────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │  Fixed Version  │                           Title                           │
├─────────┼───────────────┼──────────┼────────┼───────────────────┼─────────────────┼───────────────────────────────────────────────────────────┤
│ libc6   │ CVE-2025-4802 │ HIGH     │ fixed  │ 2.36-9+deb12u10   │ 2.36-9+deb12u11 │ glibc: static setuid binary dlopen may incorrectly search │
│         │               │          │        │                   │                 │ LD_LIBRARY_PATH                                           │
│         │               │          │        │                   │                 │ https://avd.aquasec.com/nvd/cve-2025-4802                 │
│         ├───────────────┼──────────┤        │                   ├─────────────────┼───────────────────────────────────────────────────────────┤
│         │ CVE-2025-8058 │ MEDIUM   │        │                   │ 2.36-9+deb12u13 │ glibc: Double free in glibc                               │
│         │               │          │        │                   │                 │ https://avd.aquasec.com/nvd/cve-2025-8058                 │
└─────────┴───────────────┴──────────┴────────┴───────────────────┴─────────────────┴───────────────────────────────────────────────────────────┘
Error: Process completed with exit code 1.

[optional Relevant Links:]

Any extra documentation required to understand the issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/ciCI and build related issueshelp wantedExtra attention is needed

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions