Skip to content

10.0-noble-chiseled-extra: rebuild for OpenSSL USN-8847 (CVE-2026-84782) #7384

Description

@Shman4ik

mcr.microsoft.com/dotnet/aspnet:10.0-noble-chiseled-extra (last updated 2026-09-08) ships libssl3t64 3.0.13-0ubuntu3.15. Ubuntu released 3.0.13-0ubuntu3.16 on 2026-09-29 (USN-8847-1/-2), which fixes CVE-2026-84782 (HIGH). Trivy flags it, and that blocks our image builds. Could the chiseled images be rebuilt?

Activity

  1. akorczynskikcura commented on Sep 30, 2026

    @akorczynskikcura

    The regular Ubuntu images too.

  2. lbussell commented on Sep 30, 2026

    @lbussell
    Member

    Acknowledged, taking a look.

  3. jacksonveroneze commented on Sep 30, 2026

    @jacksonveroneze

    Acknowledged, taking a look.

    This issue also affects the .NET 8 image.

  4. self-assigned this
    on Sep 30, 2026
  5. akorczynskikcura commented on Sep 30, 2026

    @akorczynskikcura

    For reference Ubuntu status https://ubuntu.com/security/CVE-2026-84782

  6. akorczynskikcura commented on Oct 2, 2026

    @akorczynskikcura

    @lbussell could you please let us know what is ETA for rebuilding Ubuntu images ? It looks like lot of people are blocked by this.

  7. added theissue type on Oct 2, 2026
  8. lbussell commented on Oct 2, 2026

    @lbussell
    Member

    Some Ubuntu (non-chiseled) images were updated overnight, and the rest are being updated now. I will update this issue when everything is done publishing.

  9. lbussell commented on Oct 2, 2026

    @lbussell
    Member

    All images have been updated. You can check for vulnerabilities with:

    docker run -t --rm aquasec/trivy:latest image --scanners vuln mcr.microsoft.com/dotnet/aspnet:10.0-noble-chiseled-extra
    ...
    ┌──────────┬────────────────┬──────────┬──────────┬───────────────────┬───────────────┬─────────────────────────────────────────────────────────────┐
    │ Library  │ Vulnerability  │ Severity │  Status  │ Installed Version │ Fixed Version │                            Title                            │
    ├──────────┼────────────────┼──────────┼──────────┼───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
    │ libc6    │ CVE-2026-18374 │ MEDIUM   │ affected │ 2.39-0ubuntu8.9   │               │ glibc: glibc: Heap buffer overflow via attacker-controlled  │
    │          │                │          │          │                   │               │ fopen mode string                                           │
    │          │                │          │          │                   │               │ https://avd.aquasec.com/nvd/cve-2026-18374                  │
    │          ├────────────────┤          │          │                   ├───────────────┼─────────────────────────────────────────────────────────────┤
    │          │ CVE-2026-89092 │          │          │                   │               │ glibc: nscd stack overflow leads to degraded DNS resolution │
    │          │                │          │          │                   │               │ https://avd.aquasec.com/nvd/cve-2026-89092                  │
    ├──────────┼────────────────┼──────────┤          ├───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤
    │ libicu74 │ CVE-2025-5222  │ LOW      │          │ 74.2-1ubuntu3.1   │               │ icu: Stack buffer overflow in the SRBRoot::addTag function  │
    │          │                │          │          │                   │               │ https://avd.aquasec.com/nvd/cve-2025-5222                   │
    └──────────┴────────────────┴──────────┴──────────┴───────────────────┴───────────────┴─────────────────────────────────────────────────────────────┘

    All fixable vulnerabilities are resolved at this time.

  10. moved this from Rollout to Done in .NET Dockeron Oct 2, 2026
  11. added
    area-dockerfilesConcerns the official .NET Dockerfiles or Dockerfile templates
    on Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area-dockerfilesConcerns the official .NET Dockerfiles or Dockerfile templatesvulnerabilityReport of a known vulnerability in an image

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions