[AutoPR- Security] Patch curl for CVE-2026-3784, CVE-2026-3783, CVE-2026-1965 [MEDIUM]#16207
Conversation
|
For CVE-2026-1965: For CVE-2026-3783: We have curl of version For CVE-2026-3784: |
|
resolved merge conflicts |
suresh-thelkar
left a comment
There was a problem hiding this comment.
Code changes look good to me. I sign off.
I have also run the full build given below. Please make sure that it runs successfully.
https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1094302&view=results
|
Full build was not successful. Checking the reason of failure. |
There was a problem hiding this comment.
All the patches almost match with respective upstream references in the changes except, 1965 -> there was a minor follow-up fix compared to launchpad one which is incorporated and mentioned as origin in patch. Full build is successful for arm64 and the partial success state due to push error for amd64 image building didn't allow other stage runs but till package building, it is fine. Buddy build is successful. Currently tests are not running likely due to restriction in pipeline environment to access to/from the upstream repos. LGTM.


Auto Patch curl for CVE-2026-3784, CVE-2026-3783, CVE-2026-1965.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1071438&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology