Vulnerability Description
Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT_SNAPSHOT_DATE alone does not set the correct timestamp value for security distribution, leading to missed security updates. This issue has been patched via commit 738bcbb.
Related Weaknesses (CWE)
References
- https://github.com/ilbers/isar/commit/3383fd808a4ced93e41e012660dfe364a3384434
- https://github.com/ilbers/isar/commit/738bcbb716c7eb7b34cbb2293cae4f264b3925fe
- https://github.com/ilbers/isar/security/advisories/GHSA-3r9w-6cp6-7hm4
FAQ
What is CVE-2025-65100?
CVE-2025-65100 is a documented vulnerability. Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT_SNAPSHOT_DATE alone does not set the correct timestamp value for security distr...
How severe is CVE-2025-65100?
CVSS scoring is not yet available for CVE-2025-65100. Check NVD for updates.
Is there a patch for CVE-2025-65100?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.