🔒️(agent) fix CRITICAL CVE-2026-63072 / CVE-2026-63073 in libssl3t64

Address the following CVEs reported by Trivy on the LiveKit agent
image against `libssl3t64` 3.5.7-1~deb13u2:

* CVE-2026-63073 — CRITICAL (CVSS 9.8)
* CVE-2026-63072

Bump `libssl3t64` to the patched version to pick up both fixes.
This commit is contained in:
lebaudantoine
2026-09-25 16:40:39 +02:00
committed by aleb_the_flash
parent 2480a76b62
commit 8d5d42cfdb
2 changed files with 2 additions and 0 deletions
+1
View File
@@ -11,6 +11,7 @@ and this project adheres to
### Fixed
- 🔒️(backend) fix CVE-2026-73228 and CVE-2026-73229 in drf
- 🔒️(agent) fix CRITICAL CVE-2026-63072 / CVE-2026-63073 in libssl3t64
## [1.32.0] - 2026-09-25
+1
View File
@@ -5,6 +5,7 @@ RUN sed -i "s|^URIs: http://|URIs: https://|" /etc/apt/sources.list.d/debian.sou
&& apt-get update && apt-get install -y --no-install-recommends \
libglib2.0-0 \
libgobject-2.0-0 \
libssl3t64 \
&& rm -rf /var/lib/apt/lists/*