Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

backport curl CVE to flatcar-3510 (LTS-2023) #1277

Merged

Conversation

sayanchowdhury
Copy link
Member

backport curl CVE to flatcar-3510 (LTS-2023)

CVEs for which patches are added

@sayanchowdhury sayanchowdhury requested a review from a team October 16, 2023 13:22
@krnowak
Copy link
Member

krnowak commented Oct 16, 2023

There was no need in moving the package to coreos-overlay - there is a user-patches setup in this version of LTS. All that was needed was to add those patches to sdk_container/src/third_party/coreos-overlay/coreos/user-patches/net-misc/curl/ directory.

@github-actions
Copy link

Build action triggered: https://github.com/flatcar/scripts/actions/runs/6534754676

@sayanchowdhury sayanchowdhury force-pushed the sayan/flatcar-3510-add-curl-patches-oct-2023 branch from 5b7c726 to ea9646a Compare October 16, 2023 16:36
CVEs for which patches are added
- CVE-2023-38545
- CVE-2023-38546

Signed-off-by: Sayan Chowdhury <schowdhury@microsoft.com>
@sayanchowdhury sayanchowdhury force-pushed the sayan/flatcar-3510-add-curl-patches-oct-2023 branch from ea9646a to 7734da3 Compare October 16, 2023 17:00
@sayanchowdhury sayanchowdhury merged commit 4b66676 into flatcar-3510 Oct 17, 2023
2 of 5 checks passed
@sayanchowdhury sayanchowdhury deleted the sayan/flatcar-3510-add-curl-patches-oct-2023 branch October 17, 2023 07:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants