Security update for cadvisor
This update for cadvisor fixes the following issues:
- update to 0.60.6:
* workflows: mirror release tags to lib/ module tags
* fs/zfs: fall back to VFS when zfs stats are unavailable
* storage/stdout: nil-check Cpu, Network, and Memory stats
* Treat memory-only NUMA nodes as valid topology
- update vendor.tar to fix
* boo#1283657, CVE-2026-63209: cadvisor:
github.com/klauspost/compress: signed integer overflow in
s2.NewDict()
-
Submitted by
Dirk Mueller (dirkmueller)
Fixed bugs
bnc#1283657
VUL-0: CVE-2026-63209: cadvisor: github.com/klauspost/compress: signed integer overflow in s2.NewDict() allows an attacker to bypass repeat index validation and cause a process crash