Description
Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT_SNAPSHOT_DATE alone does not set the correct timestamp value for security distribution, leading to missed security updates. This issue has been patched via commit 738bcbb.
Scores
CVSS v4
6.9
EPSS
0.0006
EPSS Percentile
17.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-693
Status
published
Products (1)
ilbers/isar
< 738bcbb716c7eb7b34cbb2293cae4f264b3925fe
Published
Nov 19, 2025
Tracked Since
Feb 18, 2026