Uploaded image for project: 'Clair'
  1. Clair
  2. CLAIRDEV-116

Clair does not find CVE-2022-1271 for both multiple architectures in same image

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Normal Normal
    • clair-4.8.1
    • claircore-1.5.33
    • indexer, matcher
    • None

      https://catalog.redhat.com/software/containers/openshift3/jenkins-agent-maven-35-rhel7/5ad9139ebed8bd441305ce98?container-tabs=packages has two xz-libs 5.2.2-1.el7 packages: one for x86_64 and another for i686.

      Clair is only finding CVE-2022-1271 for x86_64, but, from what I can tell, the i686 version is also affected.

      Either, I'm wrong and it's not affected (very possible) or there is some bug in Claircore.

              jcroslan@redhat.com Joseph Crosland
              rtannenb@redhat.com Ross Tannenbaum
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: