You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The CVE is against the youki / libcontainerRust project, however the vulndb automation has ingested it incorrectly as being against the github.com/opencontainers/runc Go module. Presumably this is because the CVE references a prior runc issue as a similar prior vulnerability.
This mis-association has resulted in it thinking all versions of runc are vulnerable, when in fact none are to this particular CVE.
For reference, the actual CVE against runc that is being referenced as similar in this new report was CVE-2022-29162 / GO-2022-0452 and was fixed nearly two years ago.
The text was updated successfully, but these errors were encountered:
Report ID
GO-2025-3543
Suggestion/Comment
This report is causing false positives.
The CVE is against the
youki
/libcontainer
Rust project, however the vulndb automation has ingested it incorrectly as being against thegb.xjqchip.workers.dev/opencontainers/runc
Go module. Presumably this is because the CVE references a priorrunc
issue as a similar prior vulnerability.This mis-association has resulted in it thinking all versions of
runc
are vulnerable, when in fact none are to this particular CVE.For reference, the actual CVE against
runc
that is being referenced as similar in this new report was CVE-2022-29162 / GO-2022-0452 and was fixed nearly two years ago.The text was updated successfully, but these errors were encountered: