-
Notifications
You must be signed in to change notification settings - Fork 602
[Low] Patch telegraf for CVE-2025-29923, CVE-2025-46327 #14036
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Low] Patch telegraf for CVE-2025-29923, CVE-2025-46327 #14036
Conversation
|
Patch changes are ok compared with the upstream patch. |
|
@Sumynwa. could you please share your review and signoff on this PR? |
|
@Sumynwa, gentle reminder! |
|
CVE-2025-29923.patch Upstream reference: Patch Summary of downstream patch Missing symbols: |
|
This is for all concerned, @jykanase will be taking this CVE fix forward. |
|
Closing as replaced with other PR. |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
telegraffor CVE-2025-29923telegraffor CVE-2025-46327Change Log
telegraffor CVE-2025-29923UnstableResp3as that symbol is not present in the version we ship.telegraffor CVE-2025-46327Does this affect the toolchain?
NO
Links to CVEs
Test Methodology