Skip to content

Commit e3947ab

Browse files
authored
fix(images): remediate Retina OSS image vulnerabilities (#2807)
# Description Remediate vulnerabilities across the Retina OSS Linux image set by updating Azure Linux base image versions and explicitly selecting fixed OS package versions that were not upgraded automatically from the pinned base snapshots. The changes cover `retina-agent`, `retina-init`, `retina-operator`, `retina-shell`, `kubectl-retina`, and `kubectl-retina-shell` on both AMD64 and ARM64. Enterprise images and `retina-synth` are not part of this change. | File | Change | | --- | --- | | `controller/Dockerfile` | Update Azure Linux core and distroless images to `3.0.20260909`; select PCRE2 `10.48-1.azl3` in the library-producing tools stage. | | `operator/Dockerfile` | Update distroless to `3.0.20260909`; select fixed libxml2, PCRE2, and util-linux versions in the builder whose libraries are copied into the runtime. | | `shell/Dockerfile` | Update Azure Linux core to `3.0.20260909`; select PCRE2 `10.48-1.azl3`. | | `cli/Dockerfile` | Select PCRE2 `10.48-1.azl3` in both the distroless library source and shell-enabled target. | No Go modules or application logic changed. ## Related Issue Follow-up to #2803. No separate issue is associated with this PR. ## Checklist - [x] I have read the [contributing documentation](https://retina.sh/docs/Contributing/overview). - [x] I signed and signed-off the commits (`git commit -S -s ...`). See [this documentation](https://docs.github.com/en/authentication/managing-commit-signature-verification/about-commit-signature-verification) on signing commits. - [x] I have correctly attributed the author(s) of the code. - [x] I have tested the changes locally. - [x] I have followed the project's style guidelines. - [x] I have updated the documentation, if necessary. N/A: this is an image package-version update with no user-facing behavior change. - [x] I have added tests, if applicable. N/A: existing source tests and per-platform image scans cover the change. ## Screenshots (if applicable) or Testing Completed ### Vulnerability disposition | Finding | Published/current observed version | Fixed version or disposition | Final evidence | | --- | --- | --- | --- | | `CVE-2026-84445` / gRPC | v1.83.1 | v1.83.2 | Absent from all final Go binary scans. | | `CVE-2026-56743` / Cilium | v1.19.4 | v1.19.5 | Absent from all final Go binary scans. | | `CVE-2026-56855`, `CVE-2026-78662` / `x/crypto` | v0.55.0 | v0.56.0 | Absent from all final Go binary scans. | | OpenSSL CVEs including `CVE-2026-63076` | `3.3.7-4.azl3` | `3.3.7-6.azl3` | Absent from final shell and copied-library stage scans. | | RPM `CVE-2026-44605` | `4.18.2-1.azl3` | `4.18.2-2.azl3` | Absent from final shell scans. | | PCRE2 `CVE-2026-86145`, `CVE-2026-89156`, `CVE-2026-89157`, `CVE-2026-89158`, `CVE-2026-89160` | `10.42-3.azl3` | `10.48-1.azl3` | Absent from all final image and hidden-library stage scans. | | libxml2 CVEs including `CVE-2026-74860` and `CVE-2026-86140` | `2.11.5-10.azl3` | `2.11.5-11.azl3` | Absent from the final operator builder-stage scan. | | util-linux `CVE-2026-76642`, `CVE-2026-78408`, `CVE-2026-78410` | `2.40.2-5.azl3` | `2.40.2-6.azl3` | Absent from the final operator builder-stage scan. | | `GO-2026-5932` / `x/crypto/openpgp` | Trivy reports the containing `x/crypto v0.56.0` module | Not affected / not reachable | `go list -deps`, `go mod why`, `go tool nm`, binary strings, and `govulncheck -mode=binary` confirm no OpenPGP package or symbol is compiled or called. | The published `retina-shell:v1.2.8` scan contained 144 package occurrences across 31 CVE IDs. The current-main pre-change shell build contained 46 occurrences across 13 CVE IDs. Both final shell platforms contain zero findings. ### Source validation | Command | Result | | --- | --- | | `go mod download all` | Passed | | `go mod tidy` | Passed; no module changes | | `go mod verify` | Passed; all modules verified | | `go build -o <external-output> ./cli` | Passed | | `make test` | Passed with Go 1.26.8 and bpftool 7.4.0 | | `make lint` | Passed; 0 issues | ### Final image scans Trivy v0.74.0 scanned OS packages and Go binaries in each architecture-specific OCI artifact. | Image | AMD64 | ARM64 | Final result | | --- | --- | --- | --- | | `retina-agent` | Passed | Passed | 0 findings | | `retina-init` | Passed | Passed | 0 findings | | `retina-operator` | Passed | Passed | Only `GO-2026-5932`; proven not compiled or reachable | | `retina-shell` | Passed | Passed | 0 findings | | `kubectl-retina` | Passed | Passed | Only `GO-2026-5932`; proven not compiled or reachable | | `kubectl-retina-shell` | Passed | Passed | Only `GO-2026-5932`; proven not compiled or reachable | Trivy also scanned the library-producing stages that are copied into distroless images but are not represented completely by the final RPM manifest: | Stage | AMD64 | ARM64 | | --- | --- | --- | | `controller/Dockerfile` target `tools` | 0 findings | 0 findings | | `cli/Dockerfile` target `libs` | 0 findings | 0 findings | | `operator/Dockerfile` target `builder` | Only non-reachable `GO-2026-5932` | The final ARM64 build uses the same `$BUILDPLATFORM` builder stage | ### Artifact identities | Image | Platform | OCI archive SHA-256 | | --- | --- | --- | | `retina-agent` | AMD64 | `ba079cea0b359cffc91604acb89dbcbfcf249cf19dc1c4ddfef8841dc33e271a` | | `retina-agent` | ARM64 | `971ef708af792d7d9619deebdf8f9dc3158d37c9342860111d86961ad7571953` | | `retina-init` | AMD64 | `ebc37da632d85d6f152375945deed95ec3183a3f487584b6290f3702831dad7b` | | `retina-init` | ARM64 | `f25bb822e9b9181f14d3836eebcf970f2a9549504232a09d16e20dbdc54b2c38` | | `retina-operator` | AMD64 | `9383c24244356337ffe0e43832e9bfca45c8da2f24e34395644c32eeee66c80b` | | `retina-operator` | ARM64 | `36df02fe0de559aca8a70016984826bfdd640827a7b0a050a180e9a7a4d6f539` | | `retina-shell` | AMD64 | `0a29989411814f51d63d4980a328c305ce4654b45a72814ef6cff73420930dd2` | | `retina-shell` | ARM64 | `7c39544f14914ed2745753a2080a498dc5fea3520457a7e162e77bb63c2e9a15` | | `kubectl-retina` | AMD64 | `13dea08cf8caca25e00ca2b1a8e9c91ec8694d6b712e6d294ff1cf0a6ac53bd0` | | `kubectl-retina` | ARM64 | `5b5af2cfb7db4d43fff586842fc485736fca11e5eb61d774e74be14187879963` | | `kubectl-retina-shell` | AMD64 | `8ce3f449622362d1920604b2d5007a5b51e90ad88ad12810657ad9c766865103` | | `kubectl-retina-shell` | ARM64 | `7cdebfe5af70cc8ec7251af7ad9a63b4d78be3f62e7291684e84fda26774e4e7` | ### Remaining HIGH or CRITICAL findings None. ## Additional Notes - The remaining `GO-2026-5932` Trivy entries are module-granularity matches. The affected OpenPGP packages are absent from the compiled operator and CLI binaries, and binary-mode `govulncheck` reports zero affected vulnerabilities. - Trivy reports are the local unpublished after-state. Published release telemetry will change only after fixed images are built and published. - All tools, OCI archives, caches, and scan reports were stored outside the repository. --- Please refer to the [CONTRIBUTING.md](../CONTRIBUTING.md) file for more information on how to contribute to this project. --------- Signed-off-by: mushiboy <mushi025@gmail.com>
1 parent 12eaeae commit e3947ab

4 files changed

Lines changed: 19 additions & 7 deletions

File tree

‎cli/Dockerfile‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,8 @@ RUN --mount=type=cache,target="/root/.cache/go-build" \
3030
# without the bloat of the full Go SDK image (python, gcc, systemd, etc.)
3131
# skopeo inspect docker://mcr.microsoft.com/azurelinux/base/core:3.0 --format "{{.Name}}@{{.Digest}}"
3232
FROM mcr.microsoft.com/azurelinux/base/core:3.0.20260909@sha256:34a22db497ff34a0f35ca5fc54bd38711d04238a2c1b2f65d35dc9d45dd82584 AS libs
33+
# Keep this pin until the Azure Linux base includes pcre2 >= 10.48-1.azl3; verify both architectures before removing.
34+
RUN tdnf install -y pcre2-10.48-1.azl3 && tdnf clean all
3335

3436
# Target 1: Distroless (secure, minimal)
3537
# skopeo inspect docker://mcr.microsoft.com/azurelinux/distroless/minimal:3.0 --format "{{.Name}}@{{.Digest}}"
@@ -49,10 +51,11 @@ COPY --from=builder /workspace/kubectl-retina .
4951
# kubectl-retina binary is cross-compiled for the target arch and would fail
5052
# to run inside a wrong-arch base image.
5153
FROM mcr.microsoft.com/azurelinux/base/core:3.0.20260909@sha256:34a22db497ff34a0f35ca5fc54bd38711d04238a2c1b2f65d35dc9d45dd82584 AS shell-target
54+
# Keep this pin until the Azure Linux base includes pcre2 >= 10.48-1.azl3; verify both architectures before removing.
55+
RUN tdnf install -y pcre2-10.48-1.azl3 && tdnf clean all
5256
WORKDIR /
5357
COPY --from=builder /workspace/kubectl-retina /bin/kubectl-retina
5458
RUN chmod +x /bin/kubectl-retina
5559

5660
# Default target (distroless for backward compatibility)
5761
FROM distroless-target
58-

‎controller/Dockerfile‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,10 +8,10 @@
88
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:3c78e9858004d1c43aea08829306c76c3bf870c26b98c8c07ea6ca74c54787cf AS golang
99

1010
# skopeo inspect docker://mcr.microsoft.com/azurelinux/base/core:3.0 --format "{{.Name}}@{{.Digest}}"
11-
FROM mcr.microsoft.com/azurelinux/base/core:3.0.20260825@sha256:daa1142fc6b44e27c8112ec6b4c2d579ddb9bc6b3747504e666010a45a51faa4 AS azurelinux-core
11+
FROM mcr.microsoft.com/azurelinux/base/core:3.0.20260909@sha256:34a22db497ff34a0f35ca5fc54bd38711d04238a2c1b2f65d35dc9d45dd82584 AS azurelinux-core
1212

1313
# skopeo inspect docker://mcr.microsoft.com/azurelinux/distroless/minimal:3.0 --format "{{.Name}}@{{.Digest}}"
14-
FROM mcr.microsoft.com/azurelinux/distroless/minimal:3.0.20260809@sha256:4435f90009c17fb750e5518a3f43a24a629ac4c4f8c222b50f6adfe5e0d0bf2d AS azurelinux-distroless
14+
FROM mcr.microsoft.com/azurelinux/distroless/minimal:3.0.20260909@sha256:f9aa2435862cbb05a8d7fbeb9c2d024bf7548f3838f69a96cb214c1bade88ffa AS azurelinux-distroless
1515

1616
# build stages
1717

@@ -121,11 +121,13 @@ RUN --mount=type=cache,target="/root/.cache/go-build" go build -v -o /go/bin/ret
121121

122122
# tools image
123123
FROM azurelinux-core AS tools
124+
# Keep this pin until the Azure Linux base includes pcre2 >= 10.48-1.azl3; verify both architectures before removing.
124125
RUN tdnf install -y \
125126
clang \
126127
bpftool \
127128
iproute \
128129
iptables \
130+
pcre2-10.48-1.azl3 \
129131
tcpdump \
130132
which \
131133
ca-certificates
@@ -148,7 +150,7 @@ ENTRYPOINT ["./retina/initretina"]
148150

149151
# agent final image
150152
# mcr.microsoft.com/azurelinux/distroless/minimal:3.0
151-
# mcr.microsoft.com/azurelinux/distroless/minimal@sha256:4435f90009c17fb750e5518a3f43a24a629ac4c4f8c222b50f6adfe5e0d0bf2d
153+
# mcr.microsoft.com/azurelinux/distroless/minimal@sha256:f9aa2435862cbb05a8d7fbeb9c2d024bf7548f3838f69a96cb214c1bade88ffa
152154
FROM azurelinux-distroless AS agent
153155
ENV HUBBLE_SERVER=unix:///var/run/cilium/hubble.sock
154156
COPY --from=tools /lib/ /lib

‎operator/Dockerfile‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,12 @@ ARG APP_INSIGHTS_ID
1111
WORKDIR /workspace
1212
COPY . .
1313

14-
RUN tdnf install -y jq
14+
# Keep this pin until the Azure Linux base includes pcre2 >= 10.48-1.azl3; verify both architectures before removing.
15+
RUN tdnf install -y \
16+
jq \
17+
libxml2-2.11.5-11.azl3 \
18+
pcre2-10.48-1.azl3 \
19+
util-linux-2.40.2-6.azl3
1520

1621
# Default linux/architecture.
1722
ARG GOOS=linux
@@ -36,7 +41,7 @@ RUN --mount=type=cache,target="/root/.cache/go-build" \
3641
# Final image must be $TARGETPLATFORM (default), not $BUILDPLATFORM — the
3742
# retina-operator binary is cross-compiled for the target arch and would fail
3843
# to run inside a wrong-arch base image.
39-
FROM mcr.microsoft.com/azurelinux/distroless/minimal:3.0.20260809@sha256:4435f90009c17fb750e5518a3f43a24a629ac4c4f8c222b50f6adfe5e0d0bf2d
44+
FROM mcr.microsoft.com/azurelinux/distroless/minimal:3.0.20260909@sha256:f9aa2435862cbb05a8d7fbeb9c2d024bf7548f3838f69a96cb214c1bade88ffa
4045
WORKDIR /
4146
COPY --from=builder /lib /lib
4247
COPY --from=builder /usr/lib/ /usr/lib

‎shell/Dockerfile‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,8 +26,9 @@ RUN set -eux; \
2626
./pwru --version
2727

2828
# skopeo inspect docker://mcr.microsoft.com/azurelinux/base/core:3.0 --format "{{.Name}}@{{.Digest}}"
29-
FROM mcr.microsoft.com/azurelinux/base/core:3.0.20260825@sha256:daa1142fc6b44e27c8112ec6b4c2d579ddb9bc6b3747504e666010a45a51faa4
29+
FROM mcr.microsoft.com/azurelinux/base/core:3.0.20260909@sha256:34a22db497ff34a0f35ca5fc54bd38711d04238a2c1b2f65d35dc9d45dd82584
3030

31+
# Keep this pin until the Azure Linux base includes pcre2 >= 10.48-1.azl3; verify both architectures before removing.
3132
RUN tdnf install -y \
3233
bind-utils \
3334
conntrack \
@@ -47,6 +48,7 @@ RUN tdnf install -y \
4748
nmap \
4849
nmap-ncat \
4950
openssh \
51+
pcre2-10.48-1.azl3 \
5052
procps-ng \
5153
sysstat \
5254
socat \

0 commit comments

Comments
 (0)