Skip to content

Comments

[Low] Patch subversion for CVE-2024-46901#12862

Merged
jslobodzian merged 3 commits intomicrosoft:fasttrack/3.0from
kevin-b-lockwood:kevin-b-lockwood/subversion-3.0-CVE
Apr 10, 2025
Merged

[Low] Patch subversion for CVE-2024-46901#12862
jslobodzian merged 3 commits intomicrosoft:fasttrack/3.0from
kevin-b-lockwood:kevin-b-lockwood/subversion-3.0-CVE

Conversation

@kevin-b-lockwood
Copy link
Contributor

Merge Checklist

All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)

  • The toolchain has been rebuilt successfully (or no changes were made to it)
  • The toolchain/worker package manifests are up-to-date
  • Any updated packages successfully build (or no packages were changed)
  • Packages depending on static components modified in this PR (Golang, *-static subpackages, etc.) have had their Release tag incremented.
  • Package tests (%check section) have been verified with RUN_CHECK=y for existing SPEC files, or added to new SPEC files
  • All package sources are available
  • cgmanifest files are up-to-date and sorted (./cgmanifest.json, ./toolkit/scripts/toolchain/cgmanifest.json, .github/workflows/cgmanifest.json)
  • LICENSE-MAP files are up-to-date (./LICENSES-AND-NOTICES/SPECS/data/licenses.json, ./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md, ./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)
  • All source files have up-to-date hashes in the *.signatures.json files
  • sudo make go-tidy-all and sudo make go-test-coverage pass
  • Documentation has been updated to match any changes to the build system
  • Ready to merge

Summary

Patch subversion for CVE-2024-46901

Change Log
Does this affect the toolchain?

NO

Links to CVEs
Test Methodology
  • Local build

Fails some package tests on my system before patch as well as after, could be a
my environment problem.

@kevin-b-lockwood kevin-b-lockwood requested a review from a team as a code owner March 8, 2025 00:35
@microsoft-github-policy-service microsoft-github-policy-service bot added Packaging fasttrack/3.0 PRs Destined for Azure Linux 3.0 labels Mar 8, 2025
@kevin-b-lockwood
Copy link
Contributor Author

kevin-b-lockwood commented Mar 8, 2025

This CVE patch recommends we upgrade to 1.14.5 if possible. I applied the patch here, but if I should instead update, I can do that.

@sameluch
Copy link
Contributor

This CVE patch recommends we upgrade to 1.14.5 if possible. I applied the patch here, but if I should instead update, I can do that.

After some quick review of the upstream, moving to 1.14.5 should be okay. Additionally, it looks like the upstream may fix some of the test issues on 1.14.5 for python 3.12.

@sameluch
Copy link
Contributor

@kevin-b-lockwood

@sameluch
Copy link
Contributor

/AzurePipelines run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

@Kanishk-Bansal
Copy link
Contributor

/azurepipelines run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

Copy link
Contributor

@Kanishk-Bansal Kanishk-Bansal left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

code changes LGTM, Build

@Kanishk-Bansal
Copy link
Contributor

subversion is a known failure

@jslobodzian jslobodzian merged commit 6ef576b into microsoft:fasttrack/3.0 Apr 10, 2025
17 of 20 checks passed
CBL-Mariner-Bot pushed a commit that referenced this pull request Apr 10, 2025
Co-authored-by: Sam Meluch <109628994+sameluch@users.noreply.github.com>
Co-authored-by: Kanishk Bansal <103916909+Kanishk-Bansal@users.noreply.github.com>
(cherry picked from commit 6ef576b)
@CBL-Mariner-Bot
Copy link
Collaborator

@kevin-b-lockwood kevin-b-lockwood deleted the kevin-b-lockwood/subversion-3.0-CVE branch April 10, 2025 22:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fasttrack/3.0 PRs Destined for Azure Linux 3.0 Packaging security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants