-
Notifications
You must be signed in to change notification settings - Fork 788
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[release-1.14] CVE-2024-3727 #2337
[release-1.14] CVE-2024-3727 #2337
Conversation
Ephemeral COPR build failed. @containers/packit-build please check. |
@lsm5 On this stable I’m fine with any of that, but given that this PR is intended to target the failing RHEL 8/9, I thought I’d double-check before moving forward with tagging a possibly-unwanted release. |
@lsm5 I think the packit changes should be made here. We're likely to be supporting this version for a long time on RHEL. |
what exact version will this be supported on ? Only RHEL 9? I can update the config for this branch. |
To double-check, ideally we should merge #2341, and then see the tests succeed here, is that correct? |
@TomSweeneyRedHat please rebase on latest |
This addresses CVE-2024-3727 https://issues.redhat.com/browse/OCPBUGS-33267 Signed-off-by: tomsweeneyredhat <[email protected]>
As the title says, bumping to v1.14.4 to get a release ready with the CVE-2024-3727 fix. Signed-off-by: tomsweeneyredhat <[email protected]>
03efb0b
to
ea14356
Compare
rebased and repushed, 🤞 |
Thanks again! |
Add the fix to the release-14 branch for CVE-2024-3727. This will fix the issue in OCP v4.16 and RHEL 8.10/9.4
Currently addresses: https://issues.redhat.com/browse/OCPBUGS-33267 until the RHEL 8.10 and 9.4 Jira cards are created.