-
Notifications
You must be signed in to change notification settings - Fork 148
Description
Summary
Apologies if i was not supposed to bring up open CVE's on images here. I scanned through https://groups.google.com/g/kubernetes-security-announce for the reported CVE and did not find advisory. Hence i thought of raising it here. The csi-resizer docker image built from this repository (csi-resizer:v1.13.2) contains a critical security vulnerability in the Go standard library (stdlib) due to the use of Go 1.23.8. Additionally, a high severity CVE is present in Go 1.23.10.
This impacts environments where container security policies strictly restrict known CVEs, especially critical ones.
π‘οΈ CVE Details
-
CVE-2025-22871: Affects
go-moduledue to insufficient bounds checking in certain stdlib functions. -
CVE-2025-22874: Relates to unsafe memory operations leading to denial of service or data corruption in certain environments.
π¦ Affected Image
-
Repository:
kubernetes-csi/external-resizer -
Affected Tag:
v1.13.2 -
Go base:
go1.23.1, with stdlib version1.23.8
π‘ Recommendation
Please consider updating the Go toolchain used in the build process to Go 1.24.4 or later, which fixes both CVEs.
If required, I can help submit a PR to update the Dockerfile accordingly.
π References
Summary The Docker image built from this repository (csi-resizer:v1.13.2) contains a critical security vulnerability in the Go standard library (stdlib) due to the use of Go 1.23.8. Additionally, a high severity CVE is present in Go 1.23.10.This impacts environments where container security policies strictly restrict known CVEs, especially critical ones.
π‘οΈ CVE Details
Package Go Version Fixed In CVE ID Severity CVSS Vector
stdlib go1.23.8 1.24.2 CVE-2025-22871 Critical 4.46 < 0.1
stdlib go1.23.10 1.24.4 CVE-2025-22874 High 4.14 < 0.1
CVE-2025-22871: Affects go-module due to insufficient bounds checking in certain stdlib functions.
CVE-2025-22874: Relates to unsafe memory operations leading to denial of service or data corruption in certain environments.
π¦ Affected Image
Repository: kubernetes-csi/external-resizer
Affected Tag: v1.13.2
Go base: go1.23.1, with stdlib version 1.23.8
π‘ Recommendation
Please consider updating the Go toolchain used in the build process to Go 1.24.4 or later, which fixes both CVEs.
π References
CVE-2025-22871