/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-pvg5-q5h4-c3hj

Published

Last updated

https://images.chainguard.dev/security/CGA-pvg5-q5h4-c3hj
Package

dotnet-bootstrap-8

RepositoryWolfi
Latest Update
Fix not planned
Aliases
  • CVE-2025-55315
  • GHSA-5rrx-jjjq-q2r5

Severity

9.9

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-55315

Updates

Status

Fix not planned

Impact

The dotnet-bootstrap package is used to build the dotnet package and is not meant to be installed in any image. The version of .NET shipped in the dotnet-bootstrap package is a version lower than the .NET version shipped in the dotnet package. This is due to how the dotnet build process is done as it needs to reference the previous version of .NET in order to validate that the build is done correctly and maintains API compatibility in the dotnet package. The .NET version shipped in the dotnet-bootstrap package does not reflect what is shipped in the dotnet package.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing