Skip to content

[BUG][SECURITY] v8.2.0 images flagged with Go stdlib CVEs — bump Go toolchain to 1.24.8+ #1375

Description

@sharath-reddy-baddam

What happened:
Security scanning of external‑snapshotter v8.2.0 container images (e.g., registry.k8s.io/sig-storage/snapshot-controller:v8.2.0 and registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0) reports multiple vulnerabilities in the Go standard library.
Impacted CVEs (as reported by scanners):

CVE‑2025‑61724
CVE‑2025‑61723
CVE‑2025‑58189
CVE‑2025‑58188
CVE‑2025‑58187
CVE‑2025‑47912
CVE‑2025‑58185
CVE‑2025‑61727
CVE‑2025‑61729

These are Go stdlib vulnerabilities, not issues in external‑snapshotter business logic. The fix is to rebuild binaries with a patched Go toolchain.
The Go security team states these issues are addressed in Go 1.24.8 (and 1.25.2).
What you expected to happen:

How to reproduce it:

Anything else we need to know?:

Environment:

  • Driver version:
  • Kubernetes version (use kubectl version):
  • OS (e.g. from /etc/os-release):
  • Kernel (e.g. uname -a):
  • Install tools:
  • Others:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions