Automated Flatcar security-triage review batch 30073661072, part 9 of 10.
Run metadata
Summary
This part contains 40 decision group(s).
Recommendation
Count
cleanup_keep_open
3
discovery_create_issue
2
discovery_ignore
34
discovery_update_issue
1
Confidence
Count
high
30
low
5
medium
5
Severity
Count
MEDIUM
9
n/a
31
Whole batch: 295 decision group(s) across 10 part(s).
Recommendation
Count
cleanup_keep_open
15
discovery_create_issue
18
discovery_ignore
239
discovery_kernel_routing
10
discovery_update_issue
13
Confidence
Count
high
156
low
33
medium
106
Severity
Count
HIGH
7
MEDIUM
10
n/a
278
How to use this review
Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
Close this issue with reason Completed to apply every checked, conflict-free action.
Close this issue as Not planned (or leave it open) to take no automated action at all.
Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.
Decision groups
Group 244: ammonia (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0213.html
CVEs / upstream IDs: RUSTSEC-2026-0213, GHSA-m6mh-2hw2-555x
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No production SBOM matches or other evidence shows that Flatcar ships or uses the Rust crate ammonia; this application-level XSS advisory is therefore not Flatcar-relevant.
Choose at most one (leave all unchecked to take no action for this group):
Group 245: anstream (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2024-0404.html
CVEs / upstream IDs: RUSTSEC-2024-0404, GHSA-2rxc-gjrp-vjhx
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No existing issue or SBOM evidence shows that the Rust crate anstream is shipped or used by Flatcar.
Choose at most one (leave all unchecked to take no action for this group):
Group 246: cell-project (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2020-0164.html
CVEs / upstream IDs: RUSTSEC-2020-0164, GHSA-p75v-367r-2v23
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No production SBOM or other Flatcar package evidence shows that the Rust crate cell-project is shipped or used by Flatcar.
Choose at most one (leave all unchecked to take no action for this group):
Group 247: crossbeam-deque (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2021-0093.html
CVEs / upstream IDs: CVE-2021-32810 , GHSA-pqqp-xmhj-wgcw
CVSS: 3.1
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No existing issue or production SBOM/package evidence shows that Flatcar ships or uses the Rust crate crossbeam-deque.
Choose at most one (leave all unchecked to take no action for this group):
Group 248: crossbeam-utils (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2022-0041.html
CVEs / upstream IDs: CVE-2022-23639 , GHSA-qc84-gqf4-9926 , RUSTSEC-2022-0041
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: k8s.io/utils v0.0.0-20240711033017-18e509b52bc8 (ambiguous_substring); k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738 (ambiguous_substring); k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 249: crossbeam (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2018-0009.html
CVEs / upstream IDs: CVE-2018-20996 , RUSTSEC-2018-0009, GHSA-c3cw-c387-pj65
CVSS: 3.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The advisory affects the Rust crate crossbeam, but there is no evidence that Flatcar ships or uses it, and no production SBOM package matches exist.
Choose at most one (leave all unchecked to take no action for this group):
Group 250: diesel (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0172.html
CVEs / upstream IDs: RUSTSEC-2026-0172, GHSA-ggxf-9f6j-w742
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No evidence shows that the Diesel Rust crate is shipped or used by Flatcar, and there are no production SBOM matches or existing issues.
Choose at most one (leave all unchecked to take no action for this group):
Group 251: gumdrop (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
CVEs / upstream IDs: RUSTSEC-0000-0000, HTTPS://GITHUB.COM/MURARTH/GUMDROP/ISSUES/63
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
gumdrop is an informational RustSec unmaintained-crate advisory, and the evidence contains no indication that Flatcar ships or uses it.
Choose at most one (leave all unchecked to take no action for this group):
Group 252: gumdrop (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0214.html
CVEs / upstream IDs: RUSTSEC-2026-0214, HTTPS://GITHUB.COM/MURARTH/GUMDROP/ISSUES/63
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
gumdrop is an informational RustSec unmaintained-crate advisory, and there is no evidence that Flatcar ships or uses it.
Choose at most one (leave all unchecked to take no action for this group):
Group 253: hpack (discovery, source: rustsec)
No production SBOM or other Flatcar packaging/usage evidence shows that the Rust hpack crate is shipped or used by Flatcar.
Choose at most one (leave all unchecked to take no action for this group):
Group 254: libcrux-aesgcm (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
CVEs / upstream IDs: RUSTSEC-0000-0000
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No evidence shows that the Rust crate libcrux-aesgcm is shipped or used by Flatcar, and it has no production SBOM match.
Choose at most one (leave all unchecked to take no action for this group):
Group 255: libcrux-aesgcm (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
CVEs / upstream IDs: RUSTSEC-0000-0000
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No production SBOM match or other evidence shows that Flatcar ships or uses the Rust crate libcrux-aesgcm.
Choose at most one (leave all unchecked to take no action for this group):
Group 256: libcrux-aesgcm (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
CVEs / upstream IDs: RUSTSEC-0000-0000
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
This is an informational RustSec rename/unmaintained notice for libcrux-aesgcm, not a vulnerability fix, and there is no evidence that Flatcar ships or uses the crate.
Choose at most one (leave all unchecked to take no action for this group):
Group 257: libcrux-aesgcm (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0209.html
CVEs / upstream IDs: RUSTSEC-2026-0209
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No production SBOM match or other evidence shows that Flatcar ships or uses the Rust crate libcrux-aesgcm.
Choose at most one (leave all unchecked to take no action for this group):
Group 258: libcrux-aesgcm (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0210.html
CVEs / upstream IDs: RUSTSEC-2026-0210
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The advisory concerns an unmaintained Rust crate rename, and there is no evidence that libcrux-aesgcm is shipped or used by Flatcar.
Choose at most one (leave all unchecked to take no action for this group):
Group 259: libcrux-aesgcm (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0211.html
CVEs / upstream IDs: RUSTSEC-2026-0211
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No existing issue or production SBOM/package evidence indicates that Flatcar ships or uses the Rust crate libcrux-aesgcm.
Choose at most one (leave all unchecked to take no action for this group):
Group 260: libcrux-secrets (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
CVEs / upstream IDs: RUSTSEC-0000-0000
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No production SBOM matches or other evidence shows that Flatcar ships or uses libcrux-secrets; this Rust crate is therefore not Flatcar-relevant.
Choose at most one (leave all unchecked to take no action for this group):
Group 261: libcrux-secrets (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0212.html
CVEs / upstream IDs: RUSTSEC-2026-0212
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
libcrux-secrets has no production SBOM match or other evidence of shipment or use by Flatcar; it is an unrelated Rust ecosystem advisory.
Choose at most one (leave all unchecked to take no action for this group):
Group 262: libcrux-sha3 (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
CVEs / upstream IDs: RUSTSEC-0000-0000
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No evidence shows that Flatcar ships or uses the Rust crate libcrux-sha3, and there are no production SBOM matches or existing issues.
Choose at most one (leave all unchecked to take no action for this group):
Group 263: libcrux-sha3 (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
CVEs / upstream IDs: RUSTSEC-0000-0000
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
libcrux-sha3 has no production SBOM match or other evidence of shipment or use by Flatcar, and no existing issue is present.
Choose at most one (leave all unchecked to take no action for this group):
Group 264: libcrux-sha3 (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0207.html
CVEs / upstream IDs: RUSTSEC-2026-0207
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No existing issue or SBOM/package evidence shows that Flatcar ships or uses the Rust crate libcrux-sha3; the advisory is therefore not relevant to the production image.
Choose at most one (leave all unchecked to take no action for this group):
Group 265: libcrux-sha3 (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0208.html
CVEs / upstream IDs: RUSTSEC-2026-0208
CVSS: 4.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No evidence shows that libcrux-sha3 is shipped or used by Flatcar, and there are no production SBOM matches or existing issues.
Choose at most one (leave all unchecked to take no action for this group):
Group 266: prost (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2020-0002.html
CVEs / upstream IDs: CVE-2020-35858 , GHSA-gv73-9mwv-fwgq , RUSTSEC-2020-0002
CVSS: 3.1
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The advisory affects the Rust crate prost, but the evidence contains no Flatcar shipping or usage evidence and no production SBOM matches.
Choose at most one (leave all unchecked to take no action for this group):
Group 267: rand (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0097.html
CVEs / upstream IDs: RUSTSEC-2026-0097, GHSA-cq8v-f236-94qc
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: sigs.k8s.io/randfill v1.0.0 (ambiguous_substring); sigs.k8s.io/randfill v1.0.0 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 268: replit_ruspty (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2025-0154.html
CVEs / upstream IDs: GHSA-943g-w75h-8v9h , MAL-2025-49350
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
This malicious crates.io crate has no evidence of shipment or use by Flatcar, and no production SBOM package match exists.
Choose at most one (leave all unchecked to take no action for this group):
Group 269: rustls-webpki (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0049.html
CVEs / upstream IDs: GHSA-pwjx-qhcg-rvj4 , RUSTSEC-2026-0049
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No production SBOM match or other evidence shows that Flatcar ships or uses the Rust crate rustls-webpki; this Rust ecosystem advisory is therefore not Flatcar-relevant.
Choose at most one (leave all unchecked to take no action for this group):
Group 270: rustls-webpki (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0098.html
CVEs / upstream IDs: RUSTSEC-2026-0098, GHSA-965h-392x-2mh5
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: none
Existing issue matches: none
No Flatcar production, SDK, sysext, or build-use evidence links rustls-webpki to Flatcar, and there are no SBOM package matches.
Choose at most one (leave all unchecked to take no action for this group):
Group 271: rustls-webpki (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0099.html
CVEs / upstream IDs: RUSTSEC-2026-0099, GHSA-xgp8-3hg3-c2mh
CVSS: n/a
Flatcar relevance: needs_manual_review (scope: unknown)
Recommendation: needs_manual_review (confidence: low)
SBOM matches: none
Existing issue matches: none
LLM relevance decision requested manual review.
Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-353c0c59f0dd15115009
Title: update: rustls-webpki
Name: rustls-webpki
CVEs: RUSTSEC-2026-0099, GHSA-XGP8-3HG3-C2MH
CVSSs: n/a
Action Needed: TBD
Summary: DNS name constraints were incorrectly accepted for certificates asserting wildcard names, potentially allowing names outside the permitted subtree after certificate signature verification and misissuance.
refmap.gentoo: TBD
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 272: rustls-webpki (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0104.html
CVEs / upstream IDs: RUSTSEC-2026-0104, GHSA-82j2-j2ch-gfr8
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
rustls-webpki has no production SBOM match or other evidence of being shipped or used by Flatcar, and the issue affects only applications that use CRLs.
Choose at most one (leave all unchecked to take no action for this group):
Group 273: smallstr (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
CVEs / upstream IDs: RUSTSEC-0000-0000
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
This is an informational RustSec unmaintained-crate advisory with no CVE or fixed version, and there is no evidence that Flatcar ships or uses smallstr.
Choose at most one (leave all unchecked to take no action for this group):
Group 274: smallstr (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0215.html
CVEs / upstream IDs: RUSTSEC-2026-0215
CVSS: n/a
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The unmaintained smallstr Rust crate has no evidence of being shipped or used by Flatcar, and there are no production SBOM matches or existing issues.
Choose at most one (leave all unchecked to take no action for this group):
Group 275: smallvec (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2018-0003.html
CVEs / upstream IDs: CVE-2018-20991 , GHSA-rxr4-x558-x7hw , RUSTSEC-2018-0003
CVSS: 3.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
smallvec is a Rust crate with no production SBOM match or other evidence that Flatcar ships or uses it.
Choose at most one (leave all unchecked to take no action for this group):
Group 276: smallvec (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2019-0009.html
CVEs / upstream IDs: CVE-2019-15551 , GHSA-mm7v-vpv8-xfc3
CVSS: 3.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
The Rust smallvec advisory is well-defined, but there is no evidence that Flatcar ships or uses smallvec, and no production SBOM package match exists.
Choose at most one (leave all unchecked to take no action for this group):
Group 277: smallvec (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2019-0012.html
CVEs / upstream IDs: CVE-2019-15554 , GHSA-69gw-hgj3-45m7
CVSS: 3.0
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: high)
SBOM matches: none
Existing issue matches: none
No Flatcar SBOM package match or other evidence shows that the Rust smallvec crate is shipped or used by Flatcar.
Choose at most one (leave all unchecked to take no action for this group):
Group 278: smallvec (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2021-0003.html
CVEs / upstream IDs: CVE-2021-25900 , GHSA-43w2-9j62-hq99
CVSS: 3.1
Flatcar relevance: needs_manual_review (scope: unknown)
Recommendation: needs_manual_review (confidence: low)
SBOM matches: none
Existing issue matches: none
LLM relevance decision requested manual review.
Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-3e87004edb202662606f
Title: update: smallvec
Name: smallvec
CVEs: CVE-2021-25900, GHSA-43W2-9J62-HQ99
CVSSs: 3.1
Action Needed: TBD
Summary: Heap buffer overflow and memory corruption in smallvec::SmallVec::insert_many when an iterator yields more items than its size_hint lower bound; fixed in 0.6.14 and 1.6.1.
refmap.gentoo: TBD
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 279: tar (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2021-0080.html
CVEs / upstream IDs: CVE-2021-38511
CVSS: 3.1
Flatcar relevance: relevant (scope: not_shipped)
Recommendation: update_existing_issue (confidence: medium)
SBOM matches: app-alternatives/tar 0 (exact_name); app-arch/tar 1.35 (exact_name)
Existing issue matches: update: tar #63 (open): update: tar
Gentoo Bugzilla changed for an already tracked advisory; recommend updating the existing issue.
Proposed additive update for action disc-815004c81a075deac158 (issue #63 )
Add CVEs: CVE-2021-38511
Add CVSSs: 3.1
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): Symlinks in crafted tar archives can cause tar::Archive::unpack to create directories outside the intended extraction directory; fixed in tar 0.4.36.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2021-38511
- Review Action Needed: update target
- Add upstream context: Symlinks in crafted tar archives can cause tar::Archive::unpack to create directories outside the intended extraction directory; fixed in tar 0.4.36.
- Review upstream references: https://github.com/alexcrichton/tar-rs/issues/238, CVE-2021-38511, GHSA-62jx-8vmh-4mcw
- Review Bugzilla description: # Links in archive can create arbitrary directories
When unpacking a tarball that contains a symlink the `tar` crate may create
directories outside of the directory it's supposed to unpack into.
The function errors when it's trying to create a file, but the folders are
already created at this p...
Source: https://rustsec.org/advisories/RUSTSEC-2021-0080.html
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 280: zlib-rs (discovery, source: rustsec)
Source URL: https://rustsec.org/advisories/RUSTSEC-2024-0401.html
CVEs / upstream IDs: GHSA-j3px-q95c-9683 , RUSTSEC-2024-0401
CVSS: 3.1
Flatcar relevance: not_relevant (scope: not_shipped)
Recommendation: ignore (confidence: medium)
SBOM matches: sys-libs/zlib 1.3.2-r1 (ambiguous_substring); virtual/zlib 1.3.1-r1 (ambiguous_substring)
Existing issue matches: none
LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.
Choose at most one (leave all unchecked to take no action for this group):
Group 281: #72 update: dev-lang/perl (cleanup)
Package: dev-lang/perl
CVEs: CVE-2026-13221 , CVE-2026-57432
Required fixed version (Action Needed): unparsed
Status: needs_manual_review (confidence: low)
Current issue state (at report time): open
Issue link: update: dev-lang/perl #72
SBOM matches: none
Evidence: Action Needed does not contain a parseable fixed-version requirement.; Package was not found in the Flatcar production SBOM.; No fixed-version requirement is provided, so remediation cannot be verified against the current production SBOM.; No reliable dev-lang/perl package match is present in the provided Flatcar production SBOM evidence.; Both active CVEs must be covered by a clear fixed-version comparison before closing the advisory.
Choose at most one (leave all unchecked to take no action for this group):
Group 282: #71 update: qemu (cleanup)
Package: qemu
CVEs: CVE-2026-3886
Required fixed version (Action Needed): unparsed
Status: needs_manual_review (confidence: low)
Current issue state (at report time): open
Issue link: update: qemu #71
SBOM matches: app-emulation/qemu-guest-agent 9.2.0 (unique_substring)
Evidence: Action Needed does not contain a parseable fixed-version requirement.; SBOM package matching is ambiguous or not exact.; No fixed-version requirement is provided in a machine-comparable form for the advisory.; The only SBOM match is app-emulation/qemu-guest-agent at version 9.2.0, which is not an exact match for the qemu package named by the issue.; Without a reliable package match and applicable fixed-version comparison, remediation cannot be established from the production SBOM.; SBOM package match: app-emulation/qemu-guest-agent 9.2.0 (unique_substring)
Choose at most one (leave all unchecked to take no action for this group):
Group 283: #70 update: util-linux (cleanup)
Package: util-linux
CVEs: CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-27456
Required fixed version (Action Needed): unparsed
Status: needs_manual_review (confidence: low)
Current issue state (at report time): open
Issue link: update: util-linux #70
SBOM matches: sys-apps/util-linux 2.41.4-r1 (exact_name)
Evidence: Action Needed does not contain a parseable fixed-version requirement.; The current production SBOM reliably contains sys-apps/util-linux version 2.41.4-r1.; No fixed-version requirement is provided, so it cannot be determined whether 2.41.4-r1 satisfies the remediation threshold.; All active CVEs cannot be confirmed as covered without fixed-version requirements or a clear version comparison.; SBOM package match: sys-apps/util-linux 2.41.4-r1 (exact_name)
Choose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.
Automated Flatcar security-triage review batch
30073661072, part 9 of 10.Run metadata
flatcar/security-triageflatcar/security-triage2f91672689b6bffc765a7492ea47ddc2b2d78744Summary
This part contains 40 decision group(s).
Whole batch: 295 decision group(s) across 10 part(s).
How to use this review
Decision groups
Group 244: ammonia (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0213.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 245: anstream (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2024-0404.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 246: cell-project (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2020-0164.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 247: crossbeam-deque (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2021-0093.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 248: crossbeam-utils (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2022-0041.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 249: crossbeam (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2018-0009.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 250: diesel (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0172.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 251: gumdrop (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 252: gumdrop (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0214.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 253: hpack (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2023-0085.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 254: libcrux-aesgcm (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 255: libcrux-aesgcm (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 256: libcrux-aesgcm (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 257: libcrux-aesgcm (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0209.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 258: libcrux-aesgcm (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0210.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 259: libcrux-aesgcm (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0211.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 260: libcrux-secrets (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 261: libcrux-secrets (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0212.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 262: libcrux-sha3 (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 263: libcrux-sha3 (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 264: libcrux-sha3 (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0207.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 265: libcrux-sha3 (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0208.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 266: prost (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2020-0002.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 267: rand (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0097.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 268: replit_ruspty (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2025-0154.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 269: rustls-webpki (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0049.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 270: rustls-webpki (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0098.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 271: rustls-webpki (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0099.htmlExact proposed issue for action
disc-353c0c59f0dd15115009Title:
update: rustls-webpkiLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 272: rustls-webpki (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0104.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 273: smallstr (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 274: smallstr (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0215.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 275: smallvec (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2018-0003.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 276: smallvec (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2019-0009.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 277: smallvec (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2019-0012.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 278: smallvec (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2021-0003.htmlExact proposed issue for action
disc-3e87004edb202662606fTitle:
update: smallvecLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 279: tar (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2021-0080.htmlProposed additive update for action
disc-815004c81a075deac158(issue #63)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 280: zlib-rs (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2024-0401.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 281: #72 update: dev-lang/perl (cleanup)
Choose at most one (leave all unchecked to take no action for this group):
Group 282: #71 update: qemu (cleanup)
Choose at most one (leave all unchecked to take no action for this group):
Group 283: #70 update: util-linux (cleanup)
Choose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.