Package
rancher-agent-2.11
Component
github.com/docker/docker
Latest update
8.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
github.com/docker/docker is pinned to v20.10.27+incompatible by upstream rancher/rancher via a replace directive ("rancher-machine requires a replace is set"). The fix is in moby v26.0.0+ and no fix exists in the v20.10 line. A bump attempt to a fixed release fails go mod tidy: rancher imports APIs removed in docker >= 23 (github.com/docker/docker/pkg/term; pkg/archive split into github.com/moby/go-archive). Resolution requires upstream rancher to migrate off docker 20.10.x. See: https://github.com/rancher/rancher/blob/v2.11.15/go.mod
Status
Status
Impact
Attempting to upgrade docker to version 25.0.x results in build failure. Upstream maintainers will need to fix build issues and bump Docker to a patched version in order to address CVE-2024-36623
Status
Status
Impact
rancher-agent pins the docker package version to v20.10.27+incompatible for compatibility with rancher-machine.
Status
Impact
Unable to use govulncheck to triage this advisory because the vulnerability was not found in the Go vuln DB. Treating as a true positive since we can't confirm this is a false positive.
Status