Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[Bug]: Latest Nvidia GPU Operator v26.7.1 reports large numbers of critical and high CVEs in Trivy scan output

Aperta
#2,991 3 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@rahulait ci sta già lavorando.

Dal 1/10/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

more-information-needed needs-triage

Describe the bug
Running Trivy scanner on each of the component container images of GPU Operator v26.7.1 reports following CVEs:

Severity Count Score range
Critical 49 [9.0-10]
High 3776 [7.0,9.0)
Medium 8671 [4.0,7.0)
Low 265 [1.0,4.0)

Attached zip file nvidia-gpu-operator-cve-scan-results.zip
contains:

  • Raw trivy json format reports
  • CVS format summary grouped into per-severity directory (containing per container image csv data CVE ID, CVE score, package name, package version)
  • A script to transform json raw data into CVS data

To Reproduce

  • Enumerate all container images from GPU Operator helm chart
  • Run trivy scanner to generate json format report per container image, e.g.
docker run --rm aquasec/trivy:0.74.0 image --format json "<container-image-path>" > "<container-image-name-version.json>"
  • Run the json2csv.sh script to generate CVE report, summary.

Expected behavior

Our customers deploying Nvidia GPU Operator have a security policy prohibiting OSS packages with any Critical and High CVEs (i.e. CVE score >= 7.0), their policy requires

  • either fixes to CVEs
  • or per-CVE non-exploitability confirmation/explanation
  • or per-CVE mitigation actions

Environment (please provide the following information):

  • GPU Operator Version: v26.7.1
  • OS: Ubuntu 24.04.4 LTS
  • Kernel Version: 6.17.0-35-generic
  • Container Runtime Version: containerd://2.2.5+vmware.1-fips
  • Kubernetes Distro and Version: VMware Kubernetes Service - VMware Kubernetes Release v1.35.6+vmware.1
Lingua principale
Go
Stelle
2.9k
Fork
569
Merge medio
1g 10h
PR unite (30g)
78

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di NVIDIA/gpu-operator

Tutte le issue di NVIDIA/gpu-operator

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.