Ostree Project maintains a system for managing versioned operating-system images and atomic updates, deployed primarily in container runtimes and immutable operating systems; vulnerabilities affecting this narrowly scoped project center on the ostree product itself. The durable signal reflects the limited disclosure history and the placeholder classification assigned by NVD, warranting continued observation as the project's integration across container platforms evolves; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ostree Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47085HIGH An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs. | Jul 18, 2023 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ostree Project.
Media articles that mention a CVE ID that affects a product developed by Ostree Project — matched by CVE ID, not by vendor name.