Unable to detect CVE-2023-26604 on Ubuntu 20.04 Container Image #9923
Closed
rahg0
started this conversation in
False Detection
Replies: 1 comment 1 reply
-
|
Hello @rahg0 Created aquasecurity/trivy-db#600 for this task. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
CVE-2023-26604
Description
As per Ubuntu Security Tracker, Ubuntu 20.04 is affected with CVE-2023-26604.

If we scan Ubuntu:20.04 image, We are able to see the package in question (libsystemd0 245.4-4ubuntu3.24). However, Trivy didn't flag the CVE-2023-26604 on it.
Wanted to know any reasons for this behaviour.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
ubuntu:20.04
Debug Output
Version
# trivy -v Version: 0.68.1 Vulnerability DB: Version: 2 UpdatedAt: 2025-12-10 00:28:02.128218939 +0000 UTC NextUpdate: 2025-12-11 00:28:02.128218576 +0000 UTC DownloadedAt: 2025-12-10 03:54:01.719458 +0000 UTC Java DB: Version: 1 UpdatedAt: 2025-11-25 00:56:02.039941772 +0000 UTC NextUpdate: 2025-11-28 00:56:02.039941491 +0000 UTC DownloadedAt: 2025-11-25 04:21:51.432083 +0000 UTC Check Bundle: Digest: sha256:38e239e5ab2bc9e914e69131537e92f429c4b53c108ec0ac1d7f6f91b752b9bc DownloadedAt: 2025-03-17 07:11:24.919172 +0000 UTCChecklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions