bottlerocket-os / bottlerocket-os/bottlerocket

CVE-2025-52881 is being reported by Wiz on the latest AMI

Open
#4,878 2 comments 0 reactions 0 assignees View on GitHub
status/needs-triage type/bug
Dominant language
Rust
Stars
9.7k
Forks
586
Avg merge
1d 11h
Merged PRs (30d)
11

Description

**Image I'm using:** : bottlerocket-aws-k8s-1.33-x86_64-v1.62.1-ea1afdd6

**What I expected to happen:** : CVE-2025-52881 should not be present in the latest AMI version, as it has already been addressed in the corresponding release.

**What actually happened:** I found that **CVE-2025-52881** has already been fixed in **Bottlerocket AMI v1.50.0**. Since we are already using the latest Bottlerocket AMI version, it is unexpected that **Wiz** is still reporting this vulnerability.

According to the Bottlerocket release notes, the fix is included in v1.50.0:
https://github.com/bottlerocket-os/bottlerocket/releases/tag/v1.50.0

Could you please help verify whether this is a false positive, or if there is an updated vulnerability database or additional remediation required?

**How to reproduce the problem:** : Images for reference

Image

Image

Contributor guide

Open the contributing guide

Research direction

Start by comparing Wiz's report for CVE-2025-52881 against the bottlerocket-aws-k8s-1.33-x86_64-v1.62.1 AMI and the v1.50.0 release notes linked in the issue. Verify whether the CVE remains present or is a scanner false positive, and document the required remediation or confirmation.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, linux
Domain
cloud, operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.