bottlerocket-os / bottlerocket-os/bottlerocket
CVE-2025-52881 is being reported by Wiz on the latest AMI
- Dominant language
- Rust
- Stars
- 9.7k
- Forks
- 586
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 11
Description
**Image I'm using:** : bottlerocket-aws-k8s-1.33-x86_64-v1.62.1-ea1afdd6
**What I expected to happen:** : CVE-2025-52881 should not be present in the latest AMI version, as it has already been addressed in the corresponding release.
**What actually happened:** I found that **CVE-2025-52881** has already been fixed in **Bottlerocket AMI v1.50.0**. Since we are already using the latest Bottlerocket AMI version, it is unexpected that **Wiz** is still reporting this vulnerability.
According to the Bottlerocket release notes, the fix is included in v1.50.0:
https://github.com/bottlerocket-os/bottlerocket/releases/tag/v1.50.0
Could you please help verify whether this is a false positive, or if there is an updated vulnerability database or additional remediation required?
**How to reproduce the problem:** : Images for reference
Contributor guide
Research direction
Start by comparing Wiz's report for CVE-2025-52881 against the bottlerocket-aws-k8s-1.33-x86_64-v1.62.1 AMI and the v1.50.0 release notes linked in the issue. Verify whether the CVE remains present or is a scanner false positive, and document the required remediation or confirmation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, linux
- Domain
- cloud, operating-systems, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100