# False positive on a custom image with custom python package

**URL:** <https://anchorecommunity.discourse.group/t/false-positive-on-a-custom-image-with-custom-python-package/261>\
**Category:** Grype\
**Created:** [November 29, 2024, 4:04am UTC](https://anchorecommunity.discourse.group/t/false-positive-on-a-custom-image-with-custom-python-package/261 "2024-11-29T04:04:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tony-oss-titan](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/tony-oss-titan/32/208_2.png) [@tony-oss-titan](https://anchorecommunity.discourse.group/u/tony-oss-titan)\
**Post date:** [November 29, 2024, 4:04am UTC](https://anchorecommunity.discourse.group/t/false-positive-on-a-custom-image-with-custom-python-package/261/1 "2024-11-29T04:04:17Z")

</div>

Hi, I have built a custom python alpine image with my own glibc compiled on it. Then I compiled all python packages on top. Basically got rid of all musl based dependencies.  
Now, when I run grype on this image, it still reports CVE-2024-9287. My current version of python (3.13) has this vulnerability fixed. Other scanners like trivy, docker scout, snyk do NOT report this CVE.  
I wonder why would grype keep reporting it. I waited a while thinking the grype db might need an update but seems like it has been updated for this CVE but I continue to see this for my image which is a false positive.

```auto
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
python3 3.13.0-r0 apk CVE-2024-9287 Unknown

```

I would appreciate any insight here. Thanks in advance. What additional info should I include here for someone to help debug this?

---

<div class="post-metadata">

**Author:** ![joshbressers](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/joshbressers/32/19_2.png) [@joshbressers](https://anchorecommunity.discourse.group/u/joshbressers)\
**Post date:** [December 3, 2024, 1:40am UTC](https://anchorecommunity.discourse.group/t/false-positive-on-a-custom-image-with-custom-python-package/261/2 "2024-12-03T01:40:36Z")

</div>

Hi @tony-oss-titan

It looks like Grype is reporting your Python as affected because there’s no fix for this vulnerability.

If we look at the python issue

> <https://github.com/python/cpython/issues/124651#issuecomment-2455294676>
>
> \# Bug report
> 
> \### Bug description:
> 
> Crafted paths break the script templates…:
> 
> \`\`\`console
> envname='";uname -a;"'
> mkdir "$envname"
> cd "$envname"
> python3 -m venv .
> . ./bin/activate
> \`\`\`
> 
> \`\`\`
> Linux archlinux 6.10.6-arch1-1 #1 SMP PREEMPT\_DYNAMIC Mon, 19 Aug 2024 17:02:39 +0000 x86\_64 GNU/Linux
> \`\`\`
> 
> Like pypa/virtualenv#2768 the execution path itself is low-risk, but it enables many potential downstream attack vectors. Downstream projects that automatically initialize and activate \`venv\` at a controllable path (e.g. read from repo configuration file) could execute unexpected commands.
> 
> \### CPython versions tested on:
> 
> 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, CPython main branch
> 
> \### Operating systems tested on:
> 
> Linux
> 
> 
> \### Linked PRs
> \* gh-124712
> \* gh-125813
> \* gh-125947
> \* gh-126185
> \* gh-126269
> \* gh-126300
> \* gh-126301

It looks like the fix was applied to all branches at the beginning of November

If we look at the Python releases page

> **[Download Python](https://www.python.org/downloads/)**
>
> The official home of the Python Programming Language

Python 3.13.0 was released in October

I imagine the next python version will contain this fix, but for the moment, all upstream versions of python are vulnerable

---

<div class="post-metadata">

**Author:** ![westonsteimel](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/westonsteimel/32/470_2.png) [@westonsteimel](https://anchorecommunity.discourse.group/u/westonsteimel)\
**Post date:** [December 4, 2024, 11:11am UTC](https://anchorecommunity.discourse.group/t/false-positive-on-a-custom-image-with-custom-python-package/261/3 "2024-12-04T11:11:17Z")

</div>

They have just released new versions of python that address this (along with some others), so I will get our data updated today which means they’ll be in the grype database for tomorrow

---

<div class="post-metadata">

**Author:** ![tony-oss-titan](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/tony-oss-titan/32/208_2.png) [@tony-oss-titan](https://anchorecommunity.discourse.group/u/tony-oss-titan)\
**Post date:** [December 6, 2024, 2:12am UTC](https://anchorecommunity.discourse.group/t/false-positive-on-a-custom-image-with-custom-python-package/261/4 "2024-12-06T02:12:06Z")

</div>

Thanks @westonsteimel. Please let me know if this vul was added to grype db. I can run a test to confirm
