# How to update the packages that are part of PMM Client's base docker image?

**URL:** <https://forums.percona.com/t/how-to-update-the-packages-that-are-part-of-pmm-clients-base-docker-image/34204>\
**Category:** PMM 2.x\
**Created:** [October 8, 2024, 6:46am UTC](https://forums.percona.com/t/how-to-update-the-packages-that-are-part-of-pmm-clients-base-docker-image/34204 "2024-10-08T06:46:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![chadr](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/chadr/32/3923_2.png) [@chadr](https://forums.percona.com/u/chadr)\
**Post date:** [October 8, 2024, 6:46am UTC](https://forums.percona.com/t/how-to-update-the-packages-that-are-part-of-pmm-clients-base-docker-image/34204/1 "2024-10-08T06:46:26Z")

</div>

## Description:

I’m using PMM v2.41.2 but I found that there are many vulnerability on the PMM Client docker image. So, I tried to run package manager of base docker image but I couldn’t find such things like `yum`, `dnf` and `microdnf`. How to fix the vulnerabilities of PMM Client docker image? I could upgrade the PMM to version of latest but still there is no package manager so that I couldn’t fix the vulnerabilities by myself in future.

## Steps to Reproduce:

Run vulnerability scanner like `trivy` against PMM Client docker image.

## Version:

v2.41.2

## Logs:

```auto
Total: 6 (HIGH: 6, CRITICAL: 0)

┌────────────────────────┬────────────────┬──────────┬────────┬──────────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Versi Title │
├────────────────────────┼────────────────┼──────────┼────────┼──────────────────────────────────────────────────────────────┤
│ glibc │ CVE-2024-2961 │ HIGH │ fixed │ 2.34-83.el9_3.7t of bounds write in iconv may lead to remote │
│ │ │ │ │ │
│ │ │ │ │ vd.aquasec.com/nvd/cve-2024-2961 │
│ ├────────────────┤ │ │ ──────────────────────────────────────────────┤
│ │ CVE-2024-33599 │ │ │ ack-based buffer overflow in netgroup cache │
│ │ │ │ │ vd.aquasec.com/nvd/cve-2024-33599 │
├────────────────────────┼────────────────┤ │ │ ──────────────────────────────────────────────┤
│ glibc-common │ CVE-2024-2961 │ │ │ t of bounds write in iconv may lead to remote │
│ │ │ │ │ │
│ │ │ │ │ vd.aquasec.com/nvd/cve-2024-2961 │
│ ├────────────────┤ │ │ ──────────────────────────────────────────────┤
│ │ CVE-2024-33599 │ │ │ ack-based buffer overflow in netgroup cache │
│ │ │ │ │ vd.aquasec.com/nvd/cve-2024-33599 │
├────────────────────────┼────────────────┤ │ │ ──────────────────────────────────────────────┤
│ glibc-minimal-langpack │ CVE-2024-2961 │ │ │ t of bounds write in iconv may lead to remote │
│ │ │ │ │ │
│ │ │ │ │ vd.aquasec.com/nvd/cve-2024-2961 │
│ ├────────────────┤ │ │ ──────────────────────────────────────────────┤
│ │ CVE-2024-33599 │ │ │ ack-based buffer overflow in netgroup cache │
│ │ │ │ │ vd.aquasec.com/nvd/cve-2024-33599 │
└────────────────────────┴────────────────┴──────────┴────────┴──────────────────────────────────────────────────────────────┘

```

## Expected Result:

I would like to fix the vulnerabilities by myself.

## Actual Result:

I couldn’t fix the vulnerabilities by myself as there is no package manager.

## Additional Information:

N/A

---

<div class="post-metadata">

**Author:** ![Roma\_Novikov](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/roma_novikov/32/1161_2.png) [@Roma\_Novikov](https://forums.percona.com/u/Roma_Novikov)\
**Post date:** [October 8, 2024, 2:01pm UTC](https://forums.percona.com/t/how-to-update-the-packages-that-are-part-of-pmm-clients-base-docker-image/34204/2 "2024-10-08T14:01:43Z")

</div>

Hi @chadr,  
This should already be fixed in our latest version as we have already received reports about it: [Log in with Atlassian account](https://perconadev.atlassian.net/browse/PMM-13246).  
So please upgrade, use the new images, and let us know if the problem still exists for you.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [October 8, 2024, 3:15pm UTC](https://forums.percona.com/t/how-to-update-the-packages-that-are-part-of-pmm-clients-base-docker-image/34204/3 "2024-10-08T15:15:46Z")

</div>

> [@chadr](#):
>
> I tried to run package manager of base docker image

This is unsupported behavior. Please upgrade the entire container image. We try our very best to release updated PMM images when CVEs are discovered.
