-
Notifications
You must be signed in to change notification settings - Fork 602
[Medium] Patch cert-manager for CVE-2025-32386, CVE-2025-32387, CVE-2025-22872 #13444
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Medium] Patch cert-manager for CVE-2025-32386, CVE-2025-32387, CVE-2025-22872 #13444
Conversation
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Kindly bump up release, also CVE-2025-32387 patches file are not available
Ok, I fixed it up. To clarify, CVE-2025-32386 and CVE-2025-32387 are fixed by the same patch according to upstream |
|
Updated to add a CVE that was just assigned to me |
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You have modified the upstream patch for CVE-2025-22872, Kindly create a new patch with your credentials and put the upstream reference in the patch
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Since you have changed the file names in the CVE-2025-32386 patch and modified it, it would be better to create a patch and mention the upstream patch link in the patch. Also, please refrain from adding everything to the SPEC file.
My apologies, it's something I saw on the |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
Patch
cert-managerfor CVE-2025-32386, CVE-2025-32387, and CVE-2025-22872Change Log
Does this affect the toolchain?
NO
Links to CVEs
Test Methodology