Skip to content

UID2-6929: CVE-2026-40200 upgrade musl/musl-utils to 1.2.5-r23#2494

Merged
mcollins-ttd merged 1 commit intomainfrom
syw-UID2-6929-cve-2026-40200-musl-upgrade
Apr 16, 2026
Merged

UID2-6929: CVE-2026-40200 upgrade musl/musl-utils to 1.2.5-r23#2494
mcollins-ttd merged 1 commit intomainfrom
syw-UID2-6929-cve-2026-40200-musl-upgrade

Conversation

@mcollins-ttd
Copy link
Copy Markdown
Contributor

@mcollins-ttd mcollins-ttd commented Apr 16, 2026

Summary

CVE-2026-40200 (HIGH): musl libc arbitrary code execution and denial of service vulnerability in musl/musl-utils 1.2.5-r21. Fixed in 1.2.5-r23.

Adds musl musl-utils to the existing apk upgrade in the Dockerfile so the patched packages are installed at image build time.

@mcollins-ttd mcollins-ttd merged commit 7668063 into main Apr 16, 2026
9 checks passed
@mcollins-ttd mcollins-ttd deleted the syw-UID2-6929-cve-2026-40200-musl-upgrade branch April 16, 2026 05:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants