Chainguard: hono-service-device-registry-jdbc: security update to 2.7.0-r46

high Tenable Self-Hosted Container Security Plugin ID 473845

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load()
uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by
removing the suffix, then FileOutputStream opens that predictable path without exclusive creation,
allowing another local user with access to the same shared temporary directory to create or replace the
library file before System.load() uses it. Successful exploitation depends on shared-directory
permissions, host protections, and winning the race, and can execute native code as the victim; hardened
systems may instead cause library loading to fail and fall back to Java implementations. Configurations
using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This
issue is fixed in version 1.11.4. (CVE-2026-106451)

Solution

Update the hono-service-device-registry-jdbc library and its related packages to version 2.7.0-r46 or later.

Plugin Details

Severity: High

ID: 473845

Version: Revision 1.1

Type: Local

Published: 10/8/2026

Updated: 10/8/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.38

CVSS v2

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-106451

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.3

Threat Score: 4.4

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-106451