/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-vjcq-8cwx-cgrr

Published

Last updated

https://images.chainguard.dev/security/CGA-vjcq-8cwx-cgrr
Package

k3s-1.32

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-22872
  • GHSA-vvgc-356p-c3xw

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-22872

Updates

Status

Pending upstream fix

Impact

k3s static brings in an embedded containerd-shim-runc-v2 version during it's build process. Upstream maintainers will need to fix the issue in the embedded version to address CVE

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing