Skip to content

UID2-7974: bump eclipse-temurin digest to fix openssl + libexpat Alpine CVEs - #2759

Merged
BehnamMozafari merged 2 commits into
mainfrom
bmz-UID2-7761-renew-openssl-suppression
Sep 28, 2026
Merged

BehnamMozafari merged 2 commits into
mainfrom
bmz-UID2-7761-renew-openssl-suppression

Conversation

@BehnamMozafari

@BehnamMozafari BehnamMozafari commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The Publish All Operators run
failed on CVE-2026-14456 (openssl libcrypto3/libssl3, HIGH — DoS via unbounded memory
growth in an OpenSSL QUIC server) for the Azure CC and GCP OIDC private-operator images.
This CVE was previously suppressed in .trivyignore (per reviewed rationale in #2710:
uid2-operator never runs an OpenSSL QUIC server), but that suppression's expiry
(2026-09-28) hit today.

Rather than renew the suppression, this PR fixes it properly: all three Dockerfiles
(./Dockerfile, scripts/gcp-oidc/Dockerfile, scripts/azure-cc/Dockerfile) were pinned
to a stale eclipse-temurin:21-jre-alpine-3.23 digest. The current build of that same tag
(published 2026-09-25) already ships the patched libcrypto3/libssl3 (3.5.8-r0) — no
apk upgrade workaround needed. Verified directly:

$ docker run --rm eclipse-temurin@sha256:42b42237... apk list --installed | grep -E 'libcrypto3|libssl3'
libcrypto3-3.5.8-r0 x86_64 {openssl} (Apache-2.0) [installed]
libssl3-3.5.8-r0 x86_64 {openssl} (Apache-2.0) [installed]

$ trivy image --severity HIGH,CRITICAL eclipse-temurin@sha256:42b42237...
alpine 3.23.6: 0 vulnerabilities found

This also incidentally fixes 5 other Alpine-base-image libexpat CVEs that were separately
suppressed in .trivyignore (UID2-7800, UID2-7801, UID2-7849, UID2-7962) — the trivy image
scan against the new digest came back completely clean, so those suppressions are removed
too rather than left to expire and get renewed again.

Also dropped the now-redundant apk add --no-cache --upgrade libcrypto3 libssl3 from
./Dockerfile (added in #2708 to patch the old digest) since the base image now ships the
fix directly.

Filed as UID2-7974, a new ticket
dedicated to this fix; UID2-7761, UID2-7800, UID2-7801, UID2-7849 and UID2-7962 were the
original per-CVE assessment tickets that this PR resolves.

Test plan

  • docker run ... apk list --installed confirms the new digest ships libcrypto3/libssl3 3.5.8-r0
  • trivy image against the new digest shows 0 HIGH/CRITICAL alpine findings
  • Smoke-built FROM <new digest> + RUN apk add --no-cache gcompat succeeds
  • CI vulnerability scan passes for all operator image builds (next scheduled run)

🤖 Generated with Claude Code

BehnamMozafari and others added 2 commits September 28, 2026 13:56
…rator images

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ne CVEs

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@BehnamMozafari BehnamMozafari changed the title UID2-7761: renew CVE-2026-14456 suppression for GCP/Azure private-operator images UID2-7761: bump eclipse-temurin digest to fix openssl + libexpat Alpine CVEs Sep 28, 2026
@BehnamMozafari
BehnamMozafari marked this pull request as ready for review September 28, 2026 04:40
Copilot AI lite review requested due to automatic review settings September 28, 2026 04:40
@BehnamMozafari BehnamMozafari changed the title UID2-7761: bump eclipse-temurin digest to fix openssl + libexpat Alpine CVEs UID2-7974: bump eclipse-temurin digest to fix openssl + libexpat Alpine CVEs Sep 28, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@BehnamMozafari
BehnamMozafari merged commit 5ed2624 into main Sep 28, 2026
13 of 14 checks passed
@BehnamMozafari
BehnamMozafari deleted the bmz-UID2-7761-renew-openssl-suppression branch September 28, 2026 04:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants