Skip to content

Bust Docker layer cache to fix CVE-2025-68973 (gpgv)#133

Open
willyguggenheim wants to merge 1 commit intoFusionAuth:developfrom
willyguggenheim:fix/cache-bust-gpgv-cve
Open

Bust Docker layer cache to fix CVE-2025-68973 (gpgv)#133
willyguggenheim wants to merge 1 commit intoFusionAuth:developfrom
willyguggenheim:fix/cache-bust-gpgv-cve

Conversation

@willyguggenheim
Copy link

@willyguggenheim willyguggenheim commented Feb 6, 2026

Summary

  • Add a one-time cache-bust to force apt-get update && apt-get upgrade to run on the next build, picking up the gpgv fix (2.4.4-2ubuntu17.3 → 2.4.4-2ubuntu17.4)

Motivation

The published fusionauth/fusionauth-app:latest image on Docker Hub has gpgv 2.4.4-2ubuntu17.3 which is affected by:

  • CVE-2025-68973 (HIGH) - Information disclosure and potential arbitrary code execution via out-of-bounds write in GnuPG

The Dockerfile already has apt-get -y upgrade but Docker layer caching prevents it from running. This one-line change invalidates the cached layer.

Additional note

Trivy also reports two HIGH findings in lz4-java 1.8.0 (CVE-2025-12183 and CVE-2025-66566) bundled in the FusionAuth app zip from files.fusionauth.io. These require updating the lz4-java dependency in the FusionAuth app build, which is outside the scope of this Dockerfile.

Change

-RUN apt-get update \
+RUN echo "cache-bust-2026-02-06-CVE-2025-68973" > /dev/null \
+    && apt-get update \

Test plan

  • Confirmed fusionauth/fusionauth-app:latest on Docker Hub has CVE-2025-68973 via trivy scan
  • Built locally with --build-arg FUSIONAUTH_VERSION=1.62.1 --no-cache
  • Trivy scan confirms gpgv CVE-2025-68973 is resolved (0 OS-level HIGH/CRITICAL)
  • Only remaining findings are lz4-java CVEs in the FusionAuth app artifact (not fixable in Dockerfile)

The published image has gpgv 2.4.4-2ubuntu17.3 which is affected by
CVE-2025-68973 (HIGH). The Dockerfile already runs apt-get upgrade
but the cached layer prevents it from executing. This one-time cache
bust forces a fresh apt-get update && upgrade on the next build.
@willyguggenheim willyguggenheim requested review from a team as code owners February 6, 2026 05:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant