Skip to content

Bump coredns Go and deps to fix CVEs - #352

Closed
ncopa wants to merge 2 commits into
k0sproject:mainfrom
ncopa:bump-coredns-cve-fixes
Closed

Bump coredns Go and deps to fix CVEs#352
ncopa wants to merge 2 commits into
k0sproject:mainfrom
ncopa:bump-coredns-cve-fixes

Conversation

@ncopa

@ncopa ncopa commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Bump the Go build image to 1.26.6 and add dependency overrides for
x/mod and grpc, since upstream v1.14.6 hasn't picked them up yet.
Verified with trivy: 0 vulnerabilities against the rebuilt image.

Fixes:

ncopa added 2 commits August 14, 2026 13:56
1.14.6-k0s.0 -> 1.14.6-k0s.1

Signed-off-by: Natanael Copa <ncopa@mirantis.com>
Bump the Go build image to 1.26.6 and add dependency overrides for
x/mod and grpc, since upstream v1.14.6 hasn't picked them up yet.
Verified with trivy: 0 vulnerabilities against the rebuilt image.

Fixes:
- Go stdlib: CVE-2026-39821, CVE-2026-39822, CVE-2026-46600,
  CVE-2026-42505, CVE-2026-33818, CVE-2026-56853, CVE-2026-56858,
  CVE-2026-56859, CVE-2026-56860, CVE-2026-56862
  (golang:1.26.4-alpine3.24 -> golang:1.26.6-alpine3.24)
- golang.org/x/mod: CVE-2026-56864, CVE-2026-56865 (v0.36.0 -> v0.40.0)
- google.golang.org/grpc: GHSA-hrxh-6v49-42gf (v1.82.0 -> v1.82.1)
- golang.org/x/text: CVE-2026-56852 (v0.38.0 -> v0.41.0, pulled up
  transitively by the x/mod bump, no direct override needed)

Signed-off-by: Natanael Copa <ncopa@mirantis.com>
@jnummelin jnummelin mentioned this pull request Aug 20, 2026
@jnummelin

Copy link
Copy Markdown
Member

Created bump for 1.14.7 in #359 , IMO it completely supersedes this one

@jnummelin jnummelin closed this Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants