Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1030 commits
Select commit Hold shift + click to select a range
4891d90
Merge branch '2.0' into fasttrack/2.0
jslobodzian Apr 7, 2025
2ea1b1f
Merge branch 'fasttrack/2.0' into kanbansal/etcd/CVE-2025-30204/2.0
jslobodzian Apr 7, 2025
42f9733
Merge branch 'fasttrack/2.0' into kgodara/2.0/coredns/CVE-2025-29786
jslobodzian Apr 7, 2025
dbaad5c
Merge branch 'fasttrack/2.0' into kkaitepalli/cmake-2.0-CVE-2024-48615
jslobodzian Apr 7, 2025
a1a61e5
Merge branch 'fasttrack/2.0' into sthelkar/grpc_2.0
jslobodzian Apr 7, 2025
5840860
Merge branch 'fasttrack/2.0' into ankitapareek/2.0-CVE-2025-2312-cifs…
jslobodzian Apr 7, 2025
4ccc80a
Merge branch 'fasttrack/2.0' into ankitapareek/2.0-CVE-2025-30219-rab…
jslobodzian Apr 7, 2025
d684433
Patch cmake for CVE-2024-48615 [High] (#13286)
jslobodzian Apr 7, 2025
459c8b5
Upgrade etcd to 3.5.21 for CVE-2025-30204 [High] (#13197)
jslobodzian Apr 7, 2025
8fd5fe1
Merge branch 'fasttrack/2.0' into kgodara/2.0/coredns/CVE-2025-29786
jslobodzian Apr 7, 2025
b6f7a9a
Patch coredns for CVE-2025-29786 [HIGH] (#13237)
jslobodzian Apr 7, 2025
165f299
Merge branch 'fasttrack/2.0' into ankitapareek/2.0-CVE-2025-2312-cifs…
jslobodzian Apr 7, 2025
20ff8c6
Merge branch 'fasttrack/2.0' into ankitapareek/2.0-CVE-2025-30219-rab…
jslobodzian Apr 7, 2025
b7f1d7c
Patch rabbitmq-server for CVE-2025-30219 [Medium] (#13200)
jslobodzian Apr 7, 2025
18d079a
Patch `cifs-utils` to address CVE-2025-2312 [Medium] (#13198)
jslobodzian Apr 7, 2025
de1c880
Merge branch 'fasttrack/2.0' into sthelkar/grpc_2.0
jslobodzian Apr 7, 2025
9e05142
Patch grpc for CVE-2023-31130 [Medium] (#11977)
jslobodzian Apr 7, 2025
a76e674
Patch augeas for CVE-2025-2588 [MEDIUM] (#13207)
jslobodzian Apr 7, 2025
06f38dd
Merge branch 'fasttrack/2.0' into v-smalavathu/telegraf/CVE-2025-2287…
jslobodzian Apr 7, 2025
d35c159
[Medium] Patch telegraf for CVE-2025-22870 and CVE-2024-51744 (#13245)
jslobodzian Apr 7, 2025
bed9ac8
Merge branch 'fasttrack/2.0' into sumsharma/terraform_CVE-2023-48795
jslobodzian Apr 7, 2025
2e9d273
Patch terraform for CVE-2023-48795 [Medium] (#13272)
jslobodzian Apr 7, 2025
5a2292c
Merge branch 'fasttrack/2.0' into sumsharma/kubevirt_cve-2023-48795
jslobodzian Apr 7, 2025
8cc66af
Patch kubevirt for CVE-2023-48795 [Medium] (#13273)
jslobodzian Apr 7, 2025
66f4bf3
add patch to resolve CVE-2025-21614 for cri-o
henryli001 Apr 7, 2025
9263f2e
Merge branch 'fasttrack/2.0' into skarambelkar/gdb/CVE-2022-48064-fas…
jslobodzian Apr 8, 2025
e749bf4
Patch gdb to fix CVE-2022-48064 and CVE-2022-48065 [Medium] (#13261)
jslobodzian Apr 8, 2025
38757f8
Patch erlang for CVE-2025-30211 [High] (#13269)
jslobodzian Apr 8, 2025
239643c
Patch libarchive for CVE-2024-48615 [High] (#13287)
jslobodzian Apr 8, 2025
93e5624
[High][2.0] Resolve cri-o CVE-2025-21614 (#13293)
jslobodzian Apr 8, 2025
9b512e9
Patch git-lfs for CVE-2025-22870 [Medium] (#13301)
xordux Apr 9, 2025
a5b423f
[Low] Patch python3 for CVE-2025-1795 (#12859)
v-smalavathu Apr 9, 2025
e36b904
[High] Patch qemu for CVE-2023-1544, CVE-2023-2861 (#13328)
kevin-b-lockwood Apr 10, 2025
76e4ade
Patch reaper for CVE-2024-12905 [HIGH] (#13270)
sandeepkarambelkar Apr 10, 2025
023c6c7
[Low] Patch dcos-cli for CVE-2024-51744 (#12908)
kevin-b-lockwood Apr 10, 2025
9496523
[Low] patch bpftrace for CVE-2024-2313 (#12999)
jykanase Apr 10, 2025
a0209dd
[Low] patch libtiff for CVE-2023-6228 (#13000)
jykanase Apr 10, 2025
0ee4029
[Low] Patch prometheus for CVE-2024-51744 (#13050)
v-smalavathu Apr 10, 2025
ca8bf1d
[Low]patch jx for CVE-2024-51744 (#13051)
jykanase Apr 10, 2025
433ce04
[LOW] Patch rook to fix CVE-2024-51744 (#13054)
archana25-ms Apr 10, 2025
d8937f8
[LOW] Patch cf-cli to fix CVE-2024-51744 (#13099)
archana25-ms Apr 10, 2025
2d8e7ee
[LOW] Patch unzip to fix CVE-2021-4217 (#13103)
archana25-ms Apr 10, 2025
59ed83b
Patch `wpa_supplicant` for CVE-2025-24912 [Low] (#13121)
Kanishk-Bansal Apr 10, 2025
5722282
[Low] patch cert-manager for CVE-2024-51744 (#13139)
jykanase Apr 10, 2025
7edbabe
[Low]patch kube-vip-cloud-provider for CVE-2024-51744 (#13164)
jykanase Apr 10, 2025
a571209
[Low] patch application-gateway-kubernetes-ingress for CVE-2024-51744…
jykanase Apr 10, 2025
68c7f78
[Low] Patch curl for CVE-2025-0167 (#13182)
v-smalavathu Apr 10, 2025
4a76d38
[Low] Patch kubernetes for CVE-2024-51744 (#13255)
v-smalavathu Apr 10, 2025
59350e8
[Low] Patch kubevirt for CVE-2024-51744 (#13137)
jykanase Apr 14, 2025
21b3bff
[Medium] Patch qemu for CVE-2023-3019, CVE-2023-3180, CVE-2023-3301, …
kevin-b-lockwood Apr 15, 2025
f540f44
Patch python3 for multiple CVEs in pip bundled wheel [High] (#13379)
Ankita13-code Apr 15, 2025
aabfe8f
[LOW] Patch coredns to fix CVE-2024-51744 (#13081)
archana25-ms Apr 17, 2025
2ce5022
Patch msft-golang for CVE-2025-22871 [High] (#13405)
bhagyapathak Apr 17, 2025
3710f43
Patch giflib for CVE-2025-31344 [HIGH] (#13425)
realsdx Apr 18, 2025
bd7cc09
Patch telegraf for CVE-2025-30215 [CRITICAL] (#13465)
realsdx Apr 18, 2025
a1c2b11
Upgrade erlang to 25.3.2.20 for CVE-2025-32433 [CRITICAL] (#13471)
kgodara912 Apr 18, 2025
3f4a0dd
[AUTO-PR] azure-core/azurelinux:anphel/2-perl-cve (#13485)
CBL-Mariner-Bot Apr 18, 2025
c57fad8
Patch golang-1.18 for CVE-2024-34158 [HIGH] (#13474)
kgodara912 Apr 18, 2025
1023d50
[High] Patch libsoup for CVE-2025-32913, CVE-2025-32906 (#13447)
kevin-b-lockwood Apr 18, 2025
254ce45
Patch golang for CVE-2025-22871[High] (#13403)
bhagyapathak Apr 21, 2025
05bb5e4
Patch openssh for CVE-2025-32728 [MEDIUM] (#13472)
realsdx Apr 21, 2025
a31ee21
Patch `gdb` for CVE-2022-47673, CVE-2022-47696 [High] (#13505)
Kanishk-Bansal Apr 21, 2025
feaf246
Fix `crash` for CVE-2021-20197, CVE-2022-47673, CVE-2022-47696, CVE-2…
Kanishk-Bansal Apr 22, 2025
6da1ab4
Patch `giflib` for CVE-2021-40633 [High] (#13521)
Kanishk-Bansal Apr 22, 2025
b86d953
[High] Patch moby-engine for CVE-2025-30204 (#13530)
dallasd1 Apr 22, 2025
e1c4fd5
[AUTOPATCHER-CORE] Upgrade pgbouncer to 1.24.1 to fix CVE-2025-2291 […
CBL-Mariner-Bot Apr 23, 2025
9519e1f
Merge branch 'main' into 2.0
jslobodzian Apr 24, 2025
72d0735
Upgrade `fcgi` to 2.4.5 for CVE-2025-23016 [Critical] (#13561)
Kanishk-Bansal Apr 25, 2025
92f422a
Patch `pytorch` for CVE-2025-32434, CVE-2025-3730 [Critical] (#13556)
Kanishk-Bansal Apr 25, 2025
f3a6e73
Patch libsoup for CVE-2025-32914 [HIGH] (#13581)
kgodara912 Apr 25, 2025
807e737
Patch qemu for CVE-2024-4467 [HIGH], CVE-2024-3447, CVE-2024-6505 [ME…
kgodara912 Apr 25, 2025
aa15fd3
shadow-utils: patch CVE-2023-4641[Medium] (#11925)
arc9693 Apr 28, 2025
3801314
Patch hvloader for CVE-2022-36763, CVE-2022-36764, CVE-2022-36765 [Hi…
mayankfz Apr 28, 2025
5d1d799
Merge branch 'main' into 2.0
jslobodzian Apr 29, 2025
900820e
Merge branch 'main' into 2.0
jslobodzian Apr 29, 2025
4cd96a4
Merge branch 'main' into 2.0
jslobodzian Apr 29, 2025
82c3f62
Merge branch '2.0' into fasttrack/2.0
jslobodzian May 5, 2025
3974470
[AUTOPATCHER-CORE] Upgrade redis to 6.2.18 for CVE-2025-21605 [HIGH] …
CBL-Mariner-Bot May 5, 2025
36a900a
Patch busybox for CVE-2023-39810 [HIGH] (#13652)
kgodara912 May 5, 2025
9dbc716
Patch libsoup for CVE-2025-2784 [HIGH], CVE-2025-32050, CVE-2025-3205…
kgodara912 May 5, 2025
e0c50fd
Patch hvloader for CVE-2023-45236, CVE-2023-45237 [High] (#13621)
mayankfz May 6, 2025
858974f
Switched the fast-track PR check to run on an AZL 3.0 agent pool. (#1…
PawelWMS May 8, 2025
4c88a11
[AUTO-PR] Cherry-picked CVE-2025-22247 fix in `openvm-tools` (#13761)
CBL-Mariner-Bot May 13, 2025
7d7c223
Patch `syslog-ng` for CVE-2024-47619 [High] (#13734)
Kanishk-Bansal May 13, 2025
cbf4b50
Upgrade `maven` to 3.8.1 to fix CVE-2021-26291 in `javapackages-boots…
Kanishk-Bansal May 13, 2025
1ca26a3
Revert "Upgrade `maven` to 3.8.1 to fix CVE-2021-26291 in `javapackag…
Kanishk-Bansal May 14, 2025
a093e01
Merge branch 'main' into abadawi/jun-release-2.0
CBL-Mariner-Bot Jun 2, 2025
52667b2
Abadawi/jun release 2.0 (#13942)
jslobodzian Jun 2, 2025
ec6fd3f
Merge branch '2.0' into fasttrack/2.0
jslobodzian Jun 6, 2025
6ba8798
[High] patch reaper for CVE-2025-48387 & CVE-2024-6484 (#13965)
jykanase Jun 11, 2025
4a09689
[High] patch grub2 for CVE-2025-0624 (#13938)
jykanase Jun 11, 2025
ad5b3a7
Upgrade `mysql` to 8.0.42 for fixing 25 CVEs (#13955)
Kanishk-Bansal Jun 12, 2025
434f40d
Patch `frr` for CVE-2024-55553 [High] (#13999)
Kanishk-Bansal Jun 13, 2025
f6e850d
[HIGH] Patch coredns for CVE-2025-47950 (#14021)
aninda-al Jun 17, 2025
111dbba
[High] Patch libsoup for CVE-2025-32907 (#14000)
kevin-b-lockwood Jun 17, 2025
62f1650
[High] Patch python3 for CVE-2025-4138, CVE-2025-4330, CVE-2025-4517,…
v-smalavathu Jun 17, 2025
a83411d
Patch `glibc` for CVE-2025-4802 & CVE-2025-0395 [High] (#13934)
Kanishk-Bansal Jun 19, 2025
e995767
Revert "[High] Patch python3 for CVE-2025-4138, CVE-2025-4330, CVE-20…
jslobodzian Jun 19, 2025
437afe0
Add PR package update check to fasttrack/2.0 (#14035)
rikenm1 Jun 20, 2025
b174980
Revert "Patch `glibc` for CVE-2025-4802 & CVE-2025-0395 [High] (#1393…
sameluch Jun 23, 2025
674aa65
[High] Patch protobuf for CVE-2025-4565 (#14042)
akhila-guruju Jun 24, 2025
f523c2a
Upgrade clamav to 1.0.9 to address CVE-2025-20260 [CRITICAL] (#14089)
kgodara912 Jun 26, 2025
2ab4394
[HIGH] Patch rubygem-webrick for CVE-2025-6442 (#14126)
SumitJenaHCL Jun 30, 2025
7b4e89b
[HIGH] Patch msft-golang for CVE-2025-22874 & [MEDIUM] CVE-2025-4673 …
archana25-ms Jun 30, 2025
67011b0
[AUTO-PR] azure-core/azurelinux:cve/sudo/2025-32462_2025-32463 (#14196)
CBL-Mariner-Bot Jul 1, 2025
120a9eb
Merge branch 'main' into sammeluch/2.0-merge-june25
sameluch Jul 1, 2025
7c73e67
2.0 June Update (#14199)
jslobodzian Jul 1, 2025
44703bf
Revert malformed protobuf CVE-2025-4565.patch (#14233)
jslobodzian Jul 8, 2025
ddd97d9
Revert "[High] Patch protobuf for CVE-2025-4565 (#14042)"
jslobodzian Jul 8, 2025
0dee531
Merge branch '2.0' into fasttrack/2.0
jslobodzian Jul 8, 2025
6a177c1
[HIGH] Patch bind for CVE-2024-11187 (#14100)
archana25-ms Jul 10, 2025
45a736f
[HIGH] Patch cloud-init for CVE-2024-6174 & [MEDIUM] CVE-2024-11584 (…
archana25-ms Jul 10, 2025
8e22c89
[AutoPR- Security] Patch gdk-pixbuf2 for CVE-2025-6199 (#14188)
azurelinux-security Jul 10, 2025
260b505
[2.0] Added a workaround for PR checks from forked repos. (#14217)
PawelWMS Jul 10, 2025
7f9245b
[AutoPR- Security] Patch ceph for CVE-2025-52939 (#14189)
azurelinux-security Jul 10, 2025
0802fcd
[AutoPR- Security] Patch redis for CVE-2025-32023 (#14236)
azurelinux-security Jul 10, 2025
8878610
[High] patch pam for CVE-2025-6020 (#14207)
jykanase Jul 11, 2025
58196dd
[High] Patch redis for CVE-2025-48367 (#14261)
kevin-b-lockwood Jul 11, 2025
e9888aa
[High] patch helm for CVE-2025-53547 (#14263)
jykanase Jul 11, 2025
2b47675
[High] Patch ruby for CVE-2025-6442 (#14130)
kevin-b-lockwood Jul 11, 2025
9b8d2e6
[AutoPR- Security] Patch gdk-pixbuf2 for CVE-2025-7345 (#14276)
azurelinux-security Jul 14, 2025
cbfcc95
[AutoPR- Security] Patch libssh for CVE-2025-5987, CVE-2025-5372, CVE…
azurelinux-security Jul 15, 2025
28f8d9a
[High] Patch nodejs18 for CVE-2025-23166 (#14274)
durgajagadeesh Jul 15, 2025
4736651
[High] patch git for CVE-2025-48384, CVE-2025-48385 and CVE-2025-2761…
jykanase Jul 15, 2025
c78b73f
[High] Upgrade httpd to 2.4.64 to fix CVE-2025-49812, CVE-2025-53020,…
kevin-b-lockwood Jul 15, 2025
855c5ff
[HIGH] Patch python3 for CVE-2025-6069, CVE-2025-4516, CVE-2025-50181…
aninda-al Jul 15, 2025
1709412
[AutoPR- Security] Patch gnutls for CVE-2025-6395, CVE-2025-32989, CV…
azurelinux-security Jul 18, 2025
95e7789
[AutoPR- Security] Patch sysbench for CVE-2024-25178, CVE-2024-25176 …
azurelinux-security Jul 18, 2025
c79309e
[AutoPR- Security] Patch luajit for CVE-2024-25178, CVE-2024-25176 [H…
azurelinux-security Jul 18, 2025
5593f12
[2.0] Upgrade nvidia-container-toolkit and libnvidia-container to 1.1…
sameluch Jul 25, 2025
3739436
Patch libxml2 for CVE-2025-49794, CVE-2025-49796[CRITICAL], CVE-2025-…
kgodara912 Jul 25, 2025
af77ba9
[High] Patch nodejs18 for CVE-2025-7656 (#14357)
kevin-b-lockwood Jul 25, 2025
8e11be7
[High] Patch protobuf for CVE-2025-4565 (#14363)
akhila-guruju Jul 25, 2025
fd5507a
[High] Patch qt5-qtbase for CVE-2025-6558 (#14367)
kevin-b-lockwood Jul 25, 2025
eb1469d
[AutoPR- Security] Patch jq for CVE-2025-48060 [HIGH] (#14379)
azurelinux-security Jul 25, 2025
594f5cd
Merge remote-tracking branch 'origin/main' into mbykhovtsev/monthly-sync
mbykhovtsev-ms Jul 29, 2025
20e2607
resolve merge conflict
mbykhovtsev-ms Jul 29, 2025
12803fd
[2.0] monthly release (#14409)
anphel31 Jul 29, 2025
9237b2e
Merge branch '2.0' into fasttrack/2.0
jslobodzian Aug 6, 2025
1e8f100
[2.0] Replaced PyPi's `junit-xml` module with AZL's `python3-junit-xm…
PawelWMS Aug 6, 2025
2b9c5ad
msft-golang: upgrade version 1.24.1 -> 1.24.5 (#14442)
mfrw Aug 6, 2025
1b421ae
[AutoPR- Security] Patch ceph for CVE-2024-48916 [HIGH] (#14419)
azurelinux-security Aug 8, 2025
49b7b68
[AutoPR- Security] Patch libsoup for CVE-2025-4948 [HIGH] (#14413)
azurelinux-security Aug 11, 2025
13d9817
Patch sqlite for CVE-2025-6965[HIGH], CVE-2025-7458[MEDIUM] (#14429)
kgodara912 Aug 12, 2025
76e22e5
[AutoPR- Security] Patch icu for CVE-2025-5222 [HIGH] (#14487)
azurelinux-security Aug 12, 2025
40c76f2
Patch luajit for CVE-2024-25177[HIGH] (#14436)
kgodara912 Aug 15, 2025
f46c600
[AUTOPATCHER-CORE] Upgrade postgresql to 14.19 for CVE-2025-8714, CVE…
CBL-Mariner-Bot Aug 18, 2025
187dc78
Merge branch 'main' into mbykhovtsev/aug-release
mbykhovtsev-ms Sep 2, 2025
4899b8f
Merge branch 'main' of https://github.com/microsoft/CBL-Mariner into …
mbykhovtsev-ms Sep 3, 2025
19dd9cd
[High] Patch golang & golang-1.18 for CVE-2025-47907, golang for CVE-…
akhila-guruju Sep 4, 2025
2553e1a
Merge branch 'main' of https://github.com/microsoft/CBL-Mariner into …
mbykhovtsev-ms Sep 5, 2025
622076f
Merge branch 'main' of https://github.com/microsoft/CBL-Mariner into …
mbykhovtsev-ms Sep 8, 2025
328e8fb
[2.0] August 2025 release (#14594)
anphel31 Sep 9, 2025
3afbfaa
[2.0] disable vitess-debuginfo package generation (#14715)
mbykhovtsev-ms Sep 23, 2025
b521ef4
[2.0] disable vitess-debuginfo package generation (#14715) (#14716)
anphel31 Sep 23, 2025
60c4deb
Revert "[MEDIUM] Patch glib for CVE-2024-34397 (#14223)"
PawelWMS Sep 29, 2025
76a9b76
Revert "[MEDIUM] Patch glib for CVE-2024-34397 (#14223)" (#14745)
anphel31 Sep 30, 2025
3ec1d6b
Merge branch '2.0' into fasttrack/2.0
PawelWMS Oct 3, 2025
1012e96
[2.0][toolkit] Optimized processing time of prebuilt specs (#14712)
PawelWMS Oct 3, 2025
53735b9
[2.0] Upgrade `msft-golang` to 1.24.7 (#14751)
Kanishk-Bansal Oct 3, 2025
0249490
Patch cni for CVE-2022-32149 [HIGH] and CVE-2024-45338 [MEDIUM] (#14634)
kgodara912 Oct 3, 2025
b174f1e
Patch `python3` for CVE-2025-8194 [High] (#14691)
Kanishk-Bansal Oct 3, 2025
7ff6071
[AUTOPATCHER-CORE] Upgrade perl-JSON-XS to 4.04 for CVE-2025-40928 [H…
CBL-Mariner-Bot Oct 3, 2025
4ef32c9
[AutoPR- Security] Patch cups for CVE-2025-58364, CVE-2025-58060 [HIG…
azurelinux-security Oct 3, 2025
f98f349
[AutoPR- Security] Patch libtiff for CVE-2025-9900 [HIGH] (#14736)
azurelinux-security Oct 3, 2025
f413e44
[AutoPR- Security] Patch coredns for CVE-2025-58063 [HIGH] (#14652)
azurelinux-security Oct 3, 2025
5341039
Upgrade `redis` to 6.2.20 for CVE-2025-49844 [CRITICAL] (#14828)
Kanishk-Bansal Oct 7, 2025
acf729f
[HIGH] Patch golang-1.18.8 for CVE-2025-4674 & CVE-2025-47906[MEDIUM]…
archana25-ms Oct 7, 2025
1fe046e
Merge branch 'main' into mbykhovtsev/oct-2025-rel
mbykhovtsev-ms Oct 7, 2025
501bfe2
[2.0] Upgrade `msft-golang` to 1.24.8 (#14836)
Kanishk-Bansal Oct 8, 2025
fc30f22
Merge branch 'main' of https://github.com/microsoft/CBL-Mariner into …
mbykhovtsev-ms Oct 8, 2025
a4959d6
[2.0] Enable vitess debuginfo package generation (#14850)
mbykhovtsev-ms Oct 9, 2025
ccc5b2b
[2.0] October 2025 Release (#14833)
anphel31 Oct 10, 2025
02cd34e
[AutoPR- Security] Patch qt5-qtsvg for CVE-2025-10729 [HIGH] (#14824)
azurelinux-security Oct 17, 2025
5434653
[AutoPR- Security] Patch ceph for CVE-2025-9648 [HIGH] (#14778)
azurelinux-security Oct 17, 2025
757e1e6
[2.0] Upgrade `msft-golang` to 1.24.9 (#14864)
Kanishk-Bansal Oct 17, 2025
4071738
Merge branch '2.0' into fasttrack/2.0
PawelWMS Oct 21, 2025
e016f08
[AutoPR- Security] Patch coredns for CVE-2025-59530 [HIGH] (#14932)
azurelinux-security Oct 28, 2025
6323e55
[AutoPR- Security] Patch libsoup for CVE-2025-11021 [HIGH] (#14948)
azurelinux-security Oct 30, 2025
e3a786c
[AUTOUPGRADE-CORE] Upgrade ca-certificates Msft cert change (#14722)
CBL-Mariner-Bot Oct 17, 2025
fd6b64d
[2.0] ca-certificates: revert adding 2 new root CAs (#14981)
anphel31 Oct 30, 2025
611f063
Prepare October 2025 Update 2 (#14974)
CBL-Mariner-Bot Oct 30, 2025
b6184b4
Merge changes for 2.0 monthly release with ca-certificates fix (#14983)
jslobodzian Oct 30, 2025
f430ee4
Merge branch '2.0' into fasttrack/2.0
jslobodzian Nov 3, 2025
463c58f
Merge branch 'main' into delete_me
PawelWMS Nov 6, 2025
d29f955
Merge changes for 2.0 monthly update (#15021)
jslobodzian Nov 6, 2025
d4f668b
Merge branch '2.0' into fasttrack/2.0
jslobodzian Nov 11, 2025
421b161
Upgrade runc to v1.2.8 (#15049)
liunan-ms Nov 11, 2025
abdd407
Upgrade `msft-golang` to 1.24.10 (#15040)
Kanishk-Bansal Nov 12, 2025
dfb7a56
[AutoPR- Security] Patch nodejs18 for CVE-2025-5222 [HIGH] (#15033)
azurelinux-security Nov 12, 2025
bb1a557
openssl: Fix check of unwrapped key size (#15061)
corvus-callidus Nov 12, 2025
b0abeb7
[HIGH] Patch bind for CVE-2025-8677, CVE-2025-40778 and CVE-2025-4078…
akhila-guruju Nov 13, 2025
42108e7
[High] Patch dhcp for CVE-2024-11187 (#15079)
jykanase Nov 13, 2025
7582722
Configuring network isolation for OneBranch pipelines. (#15017)
PawelWMS Nov 13, 2025
f0ae52b
[AutoPR- Security] Patch moby-containerd-cc for CVE-2025-64329, CVE-2…
azurelinux-security Nov 13, 2025
d23471b
[AutoPR- Security] Patch moby-containerd for CVE-2025-64329, CVE-2024…
azurelinux-security Nov 13, 2025
1556b69
[AutoPR- Security] Patch moby-compose for CVE-2025-47913 [HIGH] (#15120)
azurelinux-security Nov 18, 2025
544e431
[AutoPR- Security] Patch packer for CVE-2025-47913 [HIGH] (#15122)
azurelinux-security Nov 18, 2025
b0053c9
Patch qemu for CVE-2024-7409 [HIGH] (#14520)
kgodara912 Nov 21, 2025
4fd697c
[AutoPR- Security] Patch kubevirt for CVE-2025-64324 [HIGH] (#15140)
azurelinux-security Nov 21, 2025
4422ed1
[AutoPR- Security] Patch fluent-bit for CVE-2025-12970 [HIGH] (#15185)
azurelinux-security Dec 1, 2025
1c43675
[AUTOPATCHER-CORE] Upgrade libpng to 1.6.51 for CVE-2025-64505, CVE-2…
CBL-Mariner-Bot Dec 1, 2025
328d5c9
[AutoPR- Security] Patch glib for CVE-2025-13601 [HIGH] (#15181)
azurelinux-security Dec 1, 2025
e6a6cb3
Patch reaper for CVE-2018-19827 [High] and CVE-2018-19797 [Medium] (#…
akhila-guruju Dec 1, 2025
22f4c0e
Patch fluent-bit for CVE-2025-12977 [High] and CVE-2025-12969 [Medium…
BinduSri-6522866 Dec 3, 2025
d66c874
Patch reaper for CVE-2025-12816, CVE-2025-66031 [High] and CVE-2025-6…
akhila-guruju Dec 3, 2025
881f0eb
Upgrade `msft-golang` to 1.24.11 (#15221)
Kanishk-Bansal Dec 4, 2025
49861f9
[HIGH] Patch pytorch for CVE-2025-55552 (#15198)
archana25-ms Dec 5, 2025
afb0ad6
Added DigiCert root CAs to 'ca-certificates-base' (#15164)
PawelWMS Dec 5, 2025
0ee2094
[AUTOPATCHER-CORE] Upgrade `libpng` to 1.6.52 for CVE-2025-66293 [HIG…
CBL-Mariner-Bot Dec 5, 2025
040c461
merge branch main into 2.0
aaruag Dec 5, 2025
e6b5ba9
Merge changes for 2.0 monthly update (#15239)
jslobodzian Dec 5, 2025
ef72ad1
Merge branch '2.0' into fasttrack/2.0
jslobodzian Dec 16, 2025
b8dedb8
[AutoPR- Security] Patch prometheus for CVE-2025-65637 [HIGH] (#15261)
azurelinux-security Dec 16, 2025
58662cd
[AutoPR- Security] Patch moby-compose for CVE-2025-65637 [HIGH] (#15260)
azurelinux-security Dec 16, 2025
8f0265d
[AutoPR- Security] Patch moby-buildx for CVE-2025-65637 [HIGH] (#15259)
azurelinux-security Dec 16, 2025
57b6586
[AutoPR- Security] Patch kubevirt for CVE-2025-65637 [HIGH] (#15258)
azurelinux-security Dec 16, 2025
912c62b
[AutoPR- Security] Patch jx for CVE-2025-65637 [HIGH] (#15255)
azurelinux-security Dec 16, 2025
5cbb514
[AutoPR- Security] Patch flannel for CVE-2025-65637 [HIGH] (#15251)
azurelinux-security Dec 16, 2025
a40b8ef
[AutoPR- Security] Patch cert-manager for CVE-2025-65637 [HIGH] (#15245)
azurelinux-security Dec 16, 2025
31bcda5
[AutoPR- Security] Patch qt5-qtbase for CVE-2025-66293 [HIGH] (#15270)
azurelinux-security Dec 16, 2025
15becc0
[AutoPR- Security] Patch influxdb for CVE-2025-65637 [HIGH] (#15253)
azurelinux-security Dec 16, 2025
69d0841
[AutoPR- Security] Patch cf-cli for CVE-2025-65637 [HIGH] (#15246)
azurelinux-security Dec 16, 2025
b734f51
[AutoPR- Security] Patch cni-plugins for CVE-2025-65637 [HIGH] (#15247)
azurelinux-security Dec 16, 2025
996ee5b
[High] Patch kubernetes for CVE-2025-31133 (#15241)
Ratiranjan5 Dec 16, 2025
2291f3e
[AUTOPATCHER-CORE] Upgrade `httpd` to 2.4.66 for CVE-2025-55753, CVE-…
CBL-Mariner-Bot Dec 16, 2025
683ec4f
[AutoPR- Security] Patch dcos-cli for CVE-2025-65637 [HIGH] (#15250)
azurelinux-security Dec 16, 2025
663337d
[AutoPR- Security] Patch kube-vip-cloud-provider for CVE-2025-65637 […
azurelinux-security Dec 16, 2025
34f1332
[AutoPR- Security] Patch local-path-provisioner for CVE-2025-65637 [H…
azurelinux-security Dec 19, 2025
8066ae0
Revert InfluxDB change. PTEST regressed (#15357)
jslobodzian Dec 22, 2025
b9b8f8b
[AUTOPATCHER-CORE] Upgrade pgbouncer to 1.25.1 for CVE-2025-12819 (#1…
CBL-Mariner-Bot Dec 22, 2025
aa920b3
[AutoPR- Security] Patch containerized-data-importer for CVE-2025-656…
azurelinux-security Dec 22, 2025
2ab3b90
[AutoPR- Security] Patch cri-o for CVE-2025-65637 [HIGH] (#15249)
azurelinux-security Dec 22, 2025
941eb93
[AutoPR- Security] Patch python-urllib3 for CVE-2025-66471, CVE-2025-…
azurelinux-security Dec 22, 2025
12d0acc
[High] patch edk2 for CVE-2296 (#15340)
jykanase Dec 22, 2025
e75116f
[High] patch hvloader for CVE-2025-2296 (#15344)
jykanase Dec 22, 2025
2ade0ac
Revert "[AutoPR- Security] Patch python-urllib3 for CVE-2025-66471, C…
jslobodzian Dec 26, 2025
2a1be8f
[AUTOPATCHER-CORE] Upgrade `mariadb` to 10.6.24 for CVE-2025-13699 [H…
CBL-Mariner-Bot Dec 29, 2025
6841575
[AUTOPATCHER-CORE] Upgrade `php` to 8.1.34 for CVE-2025-14177, CVE-20…
CBL-Mariner-Bot Dec 29, 2025
da4bb12
[CRITICAL] Upgrade net-snmp to 5.9.5.2 for CVE-2025-68615 (#15409)
archana25-ms Dec 30, 2025
073a799
Merge branch 'main' into 2.0
jslobodzian Dec 30, 2025
13f8d1e
Merge branch '2.0' into fasttrack/2.0
jslobodzian Jan 8, 2026
8eceb6e
[AutoPR- Security] Patch strongswan for CVE-2025-62291 [HIGH] (#15526)
azurelinux-security Jan 20, 2026
5408d20
Patch libvirt for CVE-2025-12748 (#15518)
akhila-guruju Jan 20, 2026
406e074
[AutoPR- Security] Patch python-urllib3 for CVE-2025-66418, CVE-2026-…
azurelinux-security Jan 20, 2026
4185146
[HIGH] Patch frr for CVE-2025-61099,CVE-2025-61100,CVE-2025-61101,CVE…
archana25-ms Jan 23, 2026
88d37df
[High] Patch nodejs18 for CVE-2025-55131 (#15566)
v-aaditya Jan 23, 2026
670d4a4
Upgrade `msft-golang` to 1.24.12 (#15553)
Kanishk-Bansal Jan 23, 2026
871dde8
[AutoPR- Security] Patch libxml2 for CVE-2026-0992, CVE-2026-0990, CV…
azurelinux-security Jan 29, 2026
162588e
Patch hvloader for CVE-2026-22795
azurelinux-security Feb 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
583 changes: 583 additions & 0 deletions SPECS/frr/CVE-2025-61099.patch

Large diffs are not rendered by default.

Empty file.
Empty file.
Empty file.
Empty file.
Empty file.
Empty file.
Empty file.
10 changes: 8 additions & 2 deletions SPECS/frr/frr.spec
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
Summary: Routing daemon
Name: frr
Version: 8.5.5
Release: 4%{?dist}
Release: 5%{?dist}
License: GPL-2.0-or-later
Vendor: Microsoft Corporation
Distribution: Mariner
Expand All @@ -19,7 +19,9 @@ Patch4: 0004-remove-grpc-test.patch
Patch5: CVE-2024-44070.patch
Patch6: CVE-2024-55553.patch
Patch7: 0001-Fix-frr-c90-complaint-error.patch

# Following CVE fixes CVE-2025-61100, CVE-2025-61101, CVE-2025-61102, CVE-2025-61103,
# CVE-2025-61104, CVE-2025-61105, CVE-2025-61106 and CVE-2025-61107.
Patch8: CVE-2025-61099.patch
BuildRequires: autoconf
BuildRequires: automake
BuildRequires: bison
Expand Down Expand Up @@ -201,6 +203,10 @@ rm tests/lib/*grpc*
%{_sysusersdir}/%{name}.conf

%changelog
* Wed Jan 21 2026 Archana Shettigar <v-shettigara@microsoft.com> - 8.5.5-5
- Patch CVE-2025-61099, CVE-2025-61100, CVE-2025-61101, CVE-2025-61102,
CVE-2025-61103, CVE-2025-61104, CVE-2025-61105, CVE-2025-61106 and CVE-2025-61107

* Mon Dec 29 2025 Archana Shettigar <v-shettigara@microsoft.com> - 8.5.5-4
- Rebuilt for net-snmp version up with c90 fix

Expand Down
77 changes: 77 additions & 0 deletions SPECS/hvloader/CVE-2026-22795.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
From f6794d3f13d146454bad354b27b00ef4e8b724f7 Mon Sep 17 00:00:00 2001
From: Bob Beck <beck@openssl.org>
Date: Wed, 7 Jan 2026 11:29:48 -0700
Subject: [PATCH] Ensure ASN1 types are checked before use.

Some of these were fixed by LibreSSL in commit https://github.com/openbsd/src/commit/aa1f637d454961d22117b4353f98253e984b3ba8
this fix includes the other fixes in that commit, as well as fixes for others found by a scan
for a similar unvalidated access paradigm in the tree.

Reviewed-by: Kurt Roeckx <kurt@roeckx.be>
Reviewed-by: Shane Lontis <shane.lontis@oracle.com>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/29582)

Signed-off-by: Azure Linux Security Servicing Account <azurelinux-security@microsoft.com>
Upstream-reference: https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49.patch
---
CryptoPkg/Library/OpensslLib/openssl/apps/s_client.c | 3 ++-
.../OpensslLib/openssl/crypto/pkcs12/p12_kiss.c | 10 ++++++++--
.../Library/OpensslLib/openssl/crypto/pkcs7/pk7_doit.c | 2 ++
3 files changed, 12 insertions(+), 3 deletions(-)

diff --git a/CryptoPkg/Library/OpensslLib/openssl/apps/s_client.c b/CryptoPkg/Library/OpensslLib/openssl/apps/s_client.c
index 00effc80..6e8cc6e9 100644
--- a/CryptoPkg/Library/OpensslLib/openssl/apps/s_client.c
+++ b/CryptoPkg/Library/OpensslLib/openssl/apps/s_client.c
@@ -2698,8 +2698,9 @@ int s_client_main(int argc, char **argv)
goto end;
}
atyp = ASN1_generate_nconf(genstr, cnf);
- if (atyp == NULL) {
+ if (atyp == NULL || atyp->type != V_ASN1_SEQUENCE) {
NCONF_free(cnf);
+ ASN1_TYPE_free(atyp);
BIO_printf(bio_err, "ASN1_generate_nconf failed\n");
goto end;
}
diff --git a/CryptoPkg/Library/OpensslLib/openssl/crypto/pkcs12/p12_kiss.c b/CryptoPkg/Library/OpensslLib/openssl/crypto/pkcs12/p12_kiss.c
index 7ab98385..d90404dd 100644
--- a/CryptoPkg/Library/OpensslLib/openssl/crypto/pkcs12/p12_kiss.c
+++ b/CryptoPkg/Library/OpensslLib/openssl/crypto/pkcs12/p12_kiss.c
@@ -183,11 +183,17 @@ static int parse_bag(PKCS12_SAFEBAG *bag, const char *pass, int passlen,
ASN1_BMPSTRING *fname = NULL;
ASN1_OCTET_STRING *lkid = NULL;

- if ((attrib = PKCS12_SAFEBAG_get0_attr(bag, NID_friendlyName)))
+ if ((attrib = PKCS12_SAFEBAG_get0_attr(bag, NID_friendlyName))) {
+ if (attrib->type != V_ASN1_BMPSTRING)
+ return 0;
fname = attrib->value.bmpstring;
+ }

- if ((attrib = PKCS12_SAFEBAG_get0_attr(bag, NID_localKeyID)))
+ if ((attrib = PKCS12_SAFEBAG_get0_attr(bag, NID_localKeyID))) {
+ if (attrib->type != V_ASN1_OCTET_STRING)
+ return 0;
lkid = attrib->value.octet_string;
+ }

switch (PKCS12_SAFEBAG_get_nid(bag)) {
case NID_keyBag:
diff --git a/CryptoPkg/Library/OpensslLib/openssl/crypto/pkcs7/pk7_doit.c b/CryptoPkg/Library/OpensslLib/openssl/crypto/pkcs7/pk7_doit.c
index f63fbc50..4e0eb1e8 100644
--- a/CryptoPkg/Library/OpensslLib/openssl/crypto/pkcs7/pk7_doit.c
+++ b/CryptoPkg/Library/OpensslLib/openssl/crypto/pkcs7/pk7_doit.c
@@ -1092,6 +1092,8 @@ ASN1_OCTET_STRING *PKCS7_digest_from_attributes(STACK_OF(X509_ATTRIBUTE) *sk)
ASN1_TYPE *astype;
if ((astype = get_attribute(sk, NID_pkcs9_messageDigest)) == NULL)
return NULL;
+ if (astype->type != V_ASN1_OCTET_STRING)
+ return NULL;
return astype->value.octet_string;
}

--
2.45.4

6 changes: 5 additions & 1 deletion SPECS/hvloader/hvloader.spec
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
Summary: HvLoader.efi is an EFI application for loading an external hypervisor loader.
Name: hvloader
Version: 1.0.1
Release: 15%{?dist}
Release: 16%{?dist}
License: MIT
Vendor: Microsoft Corporation
Distribution: Mariner
Expand Down Expand Up @@ -36,6 +36,7 @@ Patch18: CVE-2023-45236.patch
Patch19: CVE-2024-38796.patch
Patch20: CVE-2025-3770.patch
Patch21: CVE-2025-2296.patch
Patch22: CVE-2026-22795.patch

BuildRequires: bc
BuildRequires: gcc
Expand Down Expand Up @@ -81,6 +82,9 @@ cp ./Build/MdeModule/RELEASE_GCC5/X64/MdeModulePkg/Application/%{name_github}-%{
/boot/efi/HvLoader.efi

%changelog
* Wed Feb 04 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.0.1-16
- Patch for CVE-2026-22795

* Wed Nov 20 2025 Jyoti kanase <v-jykanase@microsoft.com> - 1.0.1-15
- Patch for CVE-2025-2296

Expand Down
Loading