/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-v4gx-5w7w-pqgp

Published

Last updated

https://images.chainguard.dev/security/CGA-v4gx-5w7w-pqgp
Package

undock

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-52881
  • GHSA-cgrx-mc8f-2prm

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-52881

Updates

Status

Pending upstream fix

Impact

CVE-2025-52881 is resolved in version v1.13.0 of the dependency github.com/opencontainers/selinux. However, that version of the dependency depends on v0.6.0 of github.com/cyphar/filepath-securejoin, which introduced breaking changes (the removal of some deprecated functions). undock also depends on github.com/containers/storage, the latest version of which still relies on some of the removed functions. It's not possible to bump selinux to remediate this CVE until the storage dependency is compatible with the latest version of filepath-securejoin

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing