From 4a6b44f562ef7eb88228af02b0dbc005e2aec0bd Mon Sep 17 00:00:00 2001 From: lebaudantoine Date: Thu, 1 Oct 2026 16:23:01 +0200 Subject: [PATCH] =?UTF-8?q?=F0=9F=94=92=EF=B8=8F(agents)=20upgrade=20libpc?= =?UTF-8?q?re2-8-0=20to=20fix=20CVE-2026-103111?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The python:3.14.7-slim base image ships libpcre2-8-0 10.46-1~deb13u2, which is affected by CVE-2026-103111 (HIGH): an out-of-bounds write triggered by a crafted regular expression. Explicitly install libpcre2-8-0 in the base stage so apt pulls the patched 10.46-1~deb13u3 from trixie-security. All stages (builder, development, production) inherit the fix. This line can be dropped once an upstream python slim image ships the patched package. --- CHANGELOG.md | 1 + src/agents/Dockerfile | 1 + 2 files changed, 2 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 630269d7..14dc6eb0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -18,6 +18,7 @@ and this project adheres to - 🐛(frontend) enforce recording-mode permissions on the checkboxes - 🔒️(agents) fix util-linux CVEs reported by Cyberwatch - 🔒️(backend) fix HIGH CVEs in Django and urllib3 +- 🔒️(agents) upgrade libpcre2-8-0 to fix CVE-2026-103111 ## [1.33.0] - 2026-09-30 diff --git a/src/agents/Dockerfile b/src/agents/Dockerfile index 909e4eea..044fa0a1 100644 --- a/src/agents/Dockerfile +++ b/src/agents/Dockerfile @@ -5,6 +5,7 @@ RUN sed -i "s|^URIs: http://|URIs: https://|" /etc/apt/sources.list.d/debian.sou && apt-get update && apt-get install -y --no-install-recommends \ libglib2.0-0 \ libgobject-2.0-0 \ + libpcre2-8-0 \ libssl3t64 \ && rm -rf /var/lib/apt/lists/*