Skip to content

Security triage review: 2026-07-24 (part 9/10) #91

Description

@github-actions

Automated Flatcar security-triage review batch 30073661072, part 9 of 10.

Run metadata

Summary

This part contains 40 decision group(s).

Recommendation Count
cleanup_keep_open 3
discovery_create_issue 2
discovery_ignore 34
discovery_update_issue 1
Confidence Count
high 30
low 5
medium 5
Severity Count
MEDIUM 9
n/a 31

Whole batch: 295 decision group(s) across 10 part(s).

Recommendation Count
cleanup_keep_open 15
discovery_create_issue 18
discovery_ignore 239
discovery_kernel_routing 10
discovery_update_issue 13
Confidence Count
high 156
low 33
medium 106
Severity Count
HIGH 7
MEDIUM 10
n/a 278

How to use this review

  • Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
  • Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
  • Close this issue with reason Completed to apply every checked, conflict-free action.
  • Close this issue as Not planned (or leave it open) to take no automated action at all.
  • Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.

Decision groups

Group 244: ammonia (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0213.html
  • CVEs / upstream IDs: RUSTSEC-2026-0213, GHSA-m6mh-2hw2-555x
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM matches or other evidence shows that Flatcar ships or uses the Rust crate ammonia; this application-level XSS advisory is therefore not Flatcar-relevant.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 245: anstream (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2024-0404.html
  • CVEs / upstream IDs: RUSTSEC-2024-0404, GHSA-2rxc-gjrp-vjhx
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No existing issue or SBOM evidence shows that the Rust crate anstream is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 246: cell-project (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2020-0164.html
  • CVEs / upstream IDs: RUSTSEC-2020-0164, GHSA-p75v-367r-2v23
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM or other Flatcar package evidence shows that the Rust crate cell-project is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 247: crossbeam-deque (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2021-0093.html
  • CVEs / upstream IDs: CVE-2021-32810, GHSA-pqqp-xmhj-wgcw
  • CVSS: 3.1
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No existing issue or production SBOM/package evidence shows that Flatcar ships or uses the Rust crate crossbeam-deque.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 248: crossbeam-utils (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2022-0041.html
  • CVEs / upstream IDs: CVE-2022-23639, GHSA-qc84-gqf4-9926, RUSTSEC-2022-0041
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: k8s.io/utils v0.0.0-20240711033017-18e509b52bc8 (ambiguous_substring); k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738 (ambiguous_substring); k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 249: crossbeam (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2018-0009.html
  • CVEs / upstream IDs: CVE-2018-20996, RUSTSEC-2018-0009, GHSA-c3cw-c387-pj65
  • CVSS: 3.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory affects the Rust crate crossbeam, but there is no evidence that Flatcar ships or uses it, and no production SBOM package matches exist.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 250: diesel (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0172.html
  • CVEs / upstream IDs: RUSTSEC-2026-0172, GHSA-ggxf-9f6j-w742
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No evidence shows that the Diesel Rust crate is shipped or used by Flatcar, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 251: gumdrop (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000, HTTPS://GITHUB.COM/MURARTH/GUMDROP/ISSUES/63
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

gumdrop is an informational RustSec unmaintained-crate advisory, and the evidence contains no indication that Flatcar ships or uses it.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 252: gumdrop (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0214.html
  • CVEs / upstream IDs: RUSTSEC-2026-0214, HTTPS://GITHUB.COM/MURARTH/GUMDROP/ISSUES/63
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

gumdrop is an informational RustSec unmaintained-crate advisory, and there is no evidence that Flatcar ships or uses it.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 253: hpack (discovery, source: rustsec)

No production SBOM or other Flatcar packaging/usage evidence shows that the Rust hpack crate is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 254: libcrux-aesgcm (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No evidence shows that the Rust crate libcrux-aesgcm is shipped or used by Flatcar, and it has no production SBOM match.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 255: libcrux-aesgcm (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM match or other evidence shows that Flatcar ships or uses the Rust crate libcrux-aesgcm.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 256: libcrux-aesgcm (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

This is an informational RustSec rename/unmaintained notice for libcrux-aesgcm, not a vulnerability fix, and there is no evidence that Flatcar ships or uses the crate.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 257: libcrux-aesgcm (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0209.html
  • CVEs / upstream IDs: RUSTSEC-2026-0209
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM match or other evidence shows that Flatcar ships or uses the Rust crate libcrux-aesgcm.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 258: libcrux-aesgcm (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0210.html
  • CVEs / upstream IDs: RUSTSEC-2026-0210
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory concerns an unmaintained Rust crate rename, and there is no evidence that libcrux-aesgcm is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 259: libcrux-aesgcm (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0211.html
  • CVEs / upstream IDs: RUSTSEC-2026-0211
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No existing issue or production SBOM/package evidence indicates that Flatcar ships or uses the Rust crate libcrux-aesgcm.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 260: libcrux-secrets (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM matches or other evidence shows that Flatcar ships or uses libcrux-secrets; this Rust crate is therefore not Flatcar-relevant.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 261: libcrux-secrets (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0212.html
  • CVEs / upstream IDs: RUSTSEC-2026-0212
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

libcrux-secrets has no production SBOM match or other evidence of shipment or use by Flatcar; it is an unrelated Rust ecosystem advisory.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 262: libcrux-sha3 (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No evidence shows that Flatcar ships or uses the Rust crate libcrux-sha3, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 263: libcrux-sha3 (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

libcrux-sha3 has no production SBOM match or other evidence of shipment or use by Flatcar, and no existing issue is present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 264: libcrux-sha3 (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0207.html
  • CVEs / upstream IDs: RUSTSEC-2026-0207
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No existing issue or SBOM/package evidence shows that Flatcar ships or uses the Rust crate libcrux-sha3; the advisory is therefore not relevant to the production image.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 265: libcrux-sha3 (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0208.html
  • CVEs / upstream IDs: RUSTSEC-2026-0208
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No evidence shows that libcrux-sha3 is shipped or used by Flatcar, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 266: prost (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2020-0002.html
  • CVEs / upstream IDs: CVE-2020-35858, GHSA-gv73-9mwv-fwgq, RUSTSEC-2020-0002
  • CVSS: 3.1
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory affects the Rust crate prost, but the evidence contains no Flatcar shipping or usage evidence and no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 267: rand (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0097.html
  • CVEs / upstream IDs: RUSTSEC-2026-0097, GHSA-cq8v-f236-94qc
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: sigs.k8s.io/randfill v1.0.0 (ambiguous_substring); sigs.k8s.io/randfill v1.0.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 268: replit_ruspty (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2025-0154.html
  • CVEs / upstream IDs: GHSA-943g-w75h-8v9h, MAL-2025-49350
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

This malicious crates.io crate has no evidence of shipment or use by Flatcar, and no production SBOM package match exists.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 269: rustls-webpki (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0049.html
  • CVEs / upstream IDs: GHSA-pwjx-qhcg-rvj4, RUSTSEC-2026-0049
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM match or other evidence shows that Flatcar ships or uses the Rust crate rustls-webpki; this Rust ecosystem advisory is therefore not Flatcar-relevant.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 270: rustls-webpki (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0098.html
  • CVEs / upstream IDs: RUSTSEC-2026-0098, GHSA-965h-392x-2mh5
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: none
  • Existing issue matches: none

No Flatcar production, SDK, sysext, or build-use evidence links rustls-webpki to Flatcar, and there are no SBOM package matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 271: rustls-webpki (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0099.html
  • CVEs / upstream IDs: RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-353c0c59f0dd15115009

Title: update: rustls-webpki

Name: rustls-webpki
CVEs: RUSTSEC-2026-0099, GHSA-XGP8-3HG3-C2MH
CVSSs: n/a
Action Needed: TBD
Summary: DNS name constraints were incorrectly accepted for certificates asserting wildcard names, potentially allowing names outside the permitted subtree after certificate signature verification and misissuance.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: rustls-webpki
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 272: rustls-webpki (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0104.html
  • CVEs / upstream IDs: RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

rustls-webpki has no production SBOM match or other evidence of being shipped or used by Flatcar, and the issue affects only applications that use CRLs.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 273: smallstr (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

This is an informational RustSec unmaintained-crate advisory with no CVE or fixed version, and there is no evidence that Flatcar ships or uses smallstr.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 274: smallstr (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0215.html
  • CVEs / upstream IDs: RUSTSEC-2026-0215
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The unmaintained smallstr Rust crate has no evidence of being shipped or used by Flatcar, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 275: smallvec (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2018-0003.html
  • CVEs / upstream IDs: CVE-2018-20991, GHSA-rxr4-x558-x7hw, RUSTSEC-2018-0003
  • CVSS: 3.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

smallvec is a Rust crate with no production SBOM match or other evidence that Flatcar ships or uses it.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 276: smallvec (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2019-0009.html
  • CVEs / upstream IDs: CVE-2019-15551, GHSA-mm7v-vpv8-xfc3
  • CVSS: 3.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The Rust smallvec advisory is well-defined, but there is no evidence that Flatcar ships or uses smallvec, and no production SBOM package match exists.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 277: smallvec (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2019-0012.html
  • CVEs / upstream IDs: CVE-2019-15554, GHSA-69gw-hgj3-45m7
  • CVSS: 3.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No Flatcar SBOM package match or other evidence shows that the Rust smallvec crate is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 278: smallvec (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2021-0003.html
  • CVEs / upstream IDs: CVE-2021-25900, GHSA-43w2-9j62-hq99
  • CVSS: 3.1
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-3e87004edb202662606f

Title: update: smallvec

Name: smallvec
CVEs: CVE-2021-25900, GHSA-43W2-9J62-HQ99
CVSSs: 3.1
Action Needed: TBD
Summary: Heap buffer overflow and memory corruption in smallvec::SmallVec::insert_many when an iterator yields more items than its size_hint lower bound; fixed in 0.6.14 and 1.6.1.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: smallvec
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 279: tar (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2021-0080.html
  • CVEs / upstream IDs: CVE-2021-38511
  • CVSS: 3.1
  • Flatcar relevance: relevant (scope: not_shipped)
  • Recommendation: update_existing_issue (confidence: medium)
  • SBOM matches: app-alternatives/tar 0 (exact_name); app-arch/tar 1.35 (exact_name)
  • Existing issue matches: update: tar #63 (open): update: tar

Gentoo Bugzilla changed for an already tracked advisory; recommend updating the existing issue.

Proposed additive update for action disc-815004c81a075deac158 (issue #63)
  • Add CVEs: CVE-2021-38511
  • Add CVSSs: 3.1
  • Action Needed (only applied if currently TBD): update target
  • Summary (only applied if currently TBD): Symlinks in crafted tar archives can cause tar::Archive::unpack to create directories outside the intended extraction directory; fixed in tar 0.4.36.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2021-38511
- Review Action Needed: update target
- Add upstream context: Symlinks in crafted tar archives can cause tar::Archive::unpack to create directories outside the intended extraction directory; fixed in tar 0.4.36.
- Review upstream references: https://github.com/alexcrichton/tar-rs/issues/238, CVE-2021-38511, GHSA-62jx-8vmh-4mcw
- Review Bugzilla description: # Links in archive can create arbitrary directories

When unpacking a tarball that contains a symlink the `tar` crate may create
directories outside of the directory it's supposed to unpack into.

The function errors when it's trying to create a file, but the folders are
already created at this p...

Source: https://rustsec.org/advisories/RUSTSEC-2021-0080.html

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 280: zlib-rs (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2024-0401.html
  • CVEs / upstream IDs: GHSA-j3px-q95c-9683, RUSTSEC-2024-0401
  • CVSS: 3.1
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: sys-libs/zlib 1.3.2-r1 (ambiguous_substring); virtual/zlib 1.3.1-r1 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 281: #72 update: dev-lang/perl (cleanup)

  • Package: dev-lang/perl
  • CVEs: CVE-2026-13221, CVE-2026-57432
  • Required fixed version (Action Needed): unparsed
  • Status: needs_manual_review (confidence: low)
  • Current issue state (at report time): open
  • Issue link: update: dev-lang/perl #72
  • SBOM matches: none
  • Evidence: Action Needed does not contain a parseable fixed-version requirement.; Package was not found in the Flatcar production SBOM.; No fixed-version requirement is provided, so remediation cannot be verified against the current production SBOM.; No reliable dev-lang/perl package match is present in the provided Flatcar production SBOM evidence.; Both active CVEs must be covered by a clear fixed-version comparison before closing the advisory.

Choose at most one (leave all unchecked to take no action for this group):

Group 282: #71 update: qemu (cleanup)

  • Package: qemu
  • CVEs: CVE-2026-3886
  • Required fixed version (Action Needed): unparsed
  • Status: needs_manual_review (confidence: low)
  • Current issue state (at report time): open
  • Issue link: update: qemu #71
  • SBOM matches: app-emulation/qemu-guest-agent 9.2.0 (unique_substring)
  • Evidence: Action Needed does not contain a parseable fixed-version requirement.; SBOM package matching is ambiguous or not exact.; No fixed-version requirement is provided in a machine-comparable form for the advisory.; The only SBOM match is app-emulation/qemu-guest-agent at version 9.2.0, which is not an exact match for the qemu package named by the issue.; Without a reliable package match and applicable fixed-version comparison, remediation cannot be established from the production SBOM.; SBOM package match: app-emulation/qemu-guest-agent 9.2.0 (unique_substring)

Choose at most one (leave all unchecked to take no action for this group):

Group 283: #70 update: util-linux (cleanup)

  • Package: util-linux
  • CVEs: CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-27456
  • Required fixed version (Action Needed): unparsed
  • Status: needs_manual_review (confidence: low)
  • Current issue state (at report time): open
  • Issue link: update: util-linux #70
  • SBOM matches: sys-apps/util-linux 2.41.4-r1 (exact_name)
  • Evidence: Action Needed does not contain a parseable fixed-version requirement.; The current production SBOM reliably contains sys-apps/util-linux version 2.41.4-r1.; No fixed-version requirement is provided, so it cannot be determined whether 2.41.4-r1 satisfies the remediation threshold.; All active CVEs cannot be confirmed as covered without fixed-version requirements or a clear version comparison.; SBOM package match: sys-apps/util-linux 2.41.4-r1 (exact_name)

Choose at most one (leave all unchecked to take no action for this group):


This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-triage/reviewSecurity-triage generated review issue (approval required)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions