Skip to content

[uk-ai-resilience] [uk-ai-governance] Tier C: Unpatched Critical CVEs in container images (libc6 CVE-2026-5450) #48405

Description

@github-actions

Tier C — Restricted Pending Review

Source: UK AI Open Code Risk & Resilience Governance — 2026-07-27

Risk Scoring

Dimension Score (1–5) Notes
Exposure amplification 4 MCP server is runtime-facing; CVE in libc6 affects all process memory operations
Patchability 5 No upstream Debian fix available yet for CVE-2026-5450
Detectability 3 Memory-corruption exploits are moderately hard to detect
Operational fragility 3 Rebuilding images requires coordinated release
Ownership confidence 4 Named owners; active monitoring via container-image-scan workflow
Overall 3.8 High priority

Affected Images

Remediation Action (SLA: High — 14 days)

  1. Monitor [Debian Bookworm security tracker]((securitytracker.debian.org/redacted) for a libc6 patch
  2. When a fix is published: rebuild and re-publish both images with updated libc6
  3. Evaluate distroless or minimal base image to reduce libc6 attack surface long-term
  4. Until patched: ensure MCP server network exposure is restricted to trusted callers

Exception (temporary, expires 2026-09-27)

  • Threat hypothesis: Remote code execution via libc6 memory corruption
  • Exploit acceleration: Moderate — public CVE, no PoC observed
  • Operational weakness: Container rebuild blocked on upstream Debian patch
  • Mitigation: Network isolation + weekly Debian tracker monitoring
  • Expiry: 2026-09-27 — must be closed or renewed

Human Review Trigger

If CVE-2026-5450 PoC is published or CVSS is elevated to 9.0+, escalate to P0 rebuild immediately.

Related: #48151, #48150 | Governance discussion

Generated by UK AI Operational Resilience · sonnet46 · 83.5 AIC · ⌖ 7.39 AIC · ⊞ 5.3K ·

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions