/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-v239-vp7x-8cmh

Published

Last updated

https://images.chainguard.dev/security/CGA-v239-vp7x-8cmh
Package

rke2-runtime-1.31

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-28180
  • GHSA-c5q2-7r4c-mv6g

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-28180

Updates

Status

Pending upstream fix

Impact

This vulnerability requires non-trivial upstream code changes to replace the affected dependency. RKE2 follows upstream Kubernetes release cycle and implemented these changes in relase v1.33.0+rke2r1, see: https://docs.rke2.io/release-notes/v1.33.X#release-v1330rke2r1 Upstream Kubernetes removed this dependency in the 1.33 release, see: https://github.com/kubernetes/kubernetes/blob/2ac0bdf360cf2529a3675c7012d0bf415e1051f3/CHANGELOG/CHANGELOG-1.33.md?plain=1#L1704 The upstream maintainers of RKE2 would need to backport this fix to the 1.31 branch.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing