From 8d5d42cfdb94a8a0cf6a6bbe641dd94e3d4e8c31 Mon Sep 17 00:00:00 2001 From: lebaudantoine Date: Fri, 25 Sep 2026 16:31:36 +0200 Subject: [PATCH] =?UTF-8?q?=F0=9F=94=92=EF=B8=8F(agent)=20fix=20CRITICAL?= =?UTF-8?q?=20CVE-2026-63072=20/=20CVE-2026-63073=20in=20libssl3t64?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Address the following CVEs reported by Trivy on the LiveKit agent image against `libssl3t64` 3.5.7-1~deb13u2: * CVE-2026-63073 — CRITICAL (CVSS 9.8) * CVE-2026-63072 Bump `libssl3t64` to the patched version to pick up both fixes. --- CHANGELOG.md | 1 + src/agents/Dockerfile | 1 + 2 files changed, 2 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index c71d16a4..63ac8f77 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,7 @@ and this project adheres to ### Fixed - 🔒️(backend) fix CVE-2026-73228 and CVE-2026-73229 in drf +- 🔒️(agent) fix CRITICAL CVE-2026-63072 / CVE-2026-63073 in libssl3t64 ## [1.32.0] - 2026-09-25 diff --git a/src/agents/Dockerfile b/src/agents/Dockerfile index 5984739a..73ba973e 100644 --- a/src/agents/Dockerfile +++ b/src/agents/Dockerfile @@ -5,6 +5,7 @@ RUN sed -i "s|^URIs: http://|URIs: https://|" /etc/apt/sources.list.d/debian.sou && apt-get update && apt-get install -y --no-install-recommends \ libglib2.0-0 \ libgobject-2.0-0 \ + libssl3t64 \ && rm -rf /var/lib/apt/lists/*