Repository navigation
10.0-noble-chiseled-extra: rebuild for OpenSSL USN-8847 (CVE-2026-84782) #7384
Copy link
Copy link
Closed
Labels
area-dockerfilesConcerns the official .NET Dockerfiles or Dockerfile templatesConcerns the official .NET Dockerfiles or Dockerfile templatesvulnerabilityReport of a known vulnerability in an imageReport of a known vulnerability in an image
Description
Activity
The regular Ubuntu images too.
Acknowledged, taking a look.
Acknowledged, taking a look.
This issue also affects the .NET 8 image.
- addedvulnerabilityReport of a known vulnerability in an imageReport of a known vulnerability in an image
on Sep 30, 2026 For reference Ubuntu status https://ubuntu.com/security/CVE-2026-84782
Reacted by Jackson Veroneze@lbussell could you please let us know what is ETA for rebuilding Ubuntu images ? It looks like lot of people are blocked by this.
Some Ubuntu (non-chiseled) images were updated overnight, and the rest are being updated now. I will update this issue when everything is done publishing.
Reacted by akorczynskikcuraAll images have been updated. You can check for vulnerabilities with:
docker run -t --rm aquasec/trivy:latest image --scanners vuln mcr.microsoft.com/dotnet/aspnet:10.0-noble-chiseled-extra ... ┌──────────┬────────────────┬──────────┬──────────┬───────────────────┬───────────────┬─────────────────────────────────────────────────────────────┐ │ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │ ├──────────┼────────────────┼──────────┼──────────┼───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤ │ libc6 │ CVE-2026-18374 │ MEDIUM │ affected │ 2.39-0ubuntu8.9 │ │ glibc: glibc: Heap buffer overflow via attacker-controlled │ │ │ │ │ │ │ │ fopen mode string │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-18374 │ │ ├────────────────┤ │ │ ├───────────────┼─────────────────────────────────────────────────────────────┤ │ │ CVE-2026-89092 │ │ │ │ │ glibc: nscd stack overflow leads to degraded DNS resolution │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-89092 │ ├──────────┼────────────────┼──────────┤ ├───────────────────┼───────────────┼─────────────────────────────────────────────────────────────┤ │ libicu74 │ CVE-2025-5222 │ LOW │ │ 74.2-1ubuntu3.1 │ │ icu: Stack buffer overflow in the SRBRoot::addTag function │ │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2025-5222 │ └──────────┴────────────────┴──────────┴──────────┴───────────────────┴───────────────┴─────────────────────────────────────────────────────────────┘
All fixable vulnerabilities are resolved at this time.
Reacted by akorczynskikcura- addedarea-dockerfilesConcerns the official .NET Dockerfiles or Dockerfile templatesConcerns the official .NET Dockerfiles or Dockerfile templates
on Oct 2, 2026
Metadata
Metadata
Assignees
Labels
area-dockerfilesConcerns the official .NET Dockerfiles or Dockerfile templatesConcerns the official .NET Dockerfiles or Dockerfile templatesvulnerabilityReport of a known vulnerability in an imageReport of a known vulnerability in an image
Type
Projects
- StatusShow more project fieldsDone
mcr.microsoft.com/dotnet/aspnet:10.0-noble-chiseled-extra(last updated 2026-09-08) shipslibssl3t643.0.13-0ubuntu3.15. Ubuntu released3.0.13-0ubuntu3.16on 2026-09-29 (USN-8847-1/-2), which fixes CVE-2026-84782 (HIGH). Trivy flags it, and that blocks our image builds. Could the chiseled images be rebuilt?