Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEAT] Update openssh-server to 9.8_p1. The current version 9.7_p1 is affected by CVE-2024-6387 #90

Closed
1 task done
f-vicente opened this issue Jul 8, 2024 · 3 comments
Labels
enhancement New feature or request

Comments

@f-vicente
Copy link

Is this a new feature request?

  • I have searched the existing issues

Wanted change

The current version 9.7_p1 is affected by CVE-2024-6387. This is corrected on the latest 9.8_p1 which is available on alpine repositories https://pkgs.alpinelinux.org/packages?name=openssh-server&branch=edge&repo=&arch=&maintainer=

Reason for change

Solve CVE-2024-6387

Proposed code change

No response

@f-vicente f-vicente added the enhancement New feature or request label Jul 8, 2024
Copy link

github-actions bot commented Jul 8, 2024

Thanks for opening your first issue here! Be sure to follow the relevant issue templates, or risk having this issue marked as invalid.

@thespad
Copy link
Member

thespad commented Jul 8, 2024

Alpine does not use glibc and is not affected by CVE-2024-6387 and the package link you have provided is for Edge, which is their rolling release, not for 3.20 which is the version of Alpine that this image uses.

@thespad thespad closed this as completed Jul 8, 2024
@LinuxServer-CI LinuxServer-CI moved this from Issues to Done in Issue & PR Tracker Jul 8, 2024
@f-vicente
Copy link
Author

Thanks @thespad

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Archived in project
Development

No branches or pull requests

2 participants