-
Notifications
You must be signed in to change notification settings - Fork 590
[Medium] Patch kubevirt for CVE-2024-33394 #14315
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
[Medium] Patch kubevirt for CVE-2024-33394 #14315
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Triggered Test Build.
Reviewing patch meanwhile.
@@ -225,6 +226,9 @@ install -p -m 0644 cmd/virt-handler/nsswitch.conf %{buildroot}%{_datadir}/kube-v | |||
%{_bindir}/virt-tests | |||
|
|||
%changelog | |||
* Fri Jul 11 2025 BinduSri Adabala <[email protected]> - 0.59.0-29 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Test Build Triggered: link
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM :)
@LeoMar4 / @0xba1a / @kgodara912 , gentle reminder for review and approval! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Signed-Off By: Muhammad Falak.
LGTM - the changes are ok to be merged.
@Malateshk007 Please wait for FTE signoff before seeking stable-maintainer approval. |
SPECS/kubevirt/kubevirt.spec
Outdated
@@ -45,6 +45,7 @@ Patch12: CVE-2025-22869.patch | |||
Patch13: CVE-2023-48795.patch | |||
Patch14: CVE-2024-51744.patch | |||
Patch15: CVE-2025-22872.patch | |||
Patch16: CVE-2024-33394.patch |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please use spaces instead of tab
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Addressed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Minor whitespace change required.
e958437
to
d077b8d
Compare
@LeoMar4 / @0xba1a / @kgodara912 , gentle reminder for review and approval! |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-static
subpackages, etc.) have had theirRelease
tag incremented../cgmanifest.json
,./toolkit/scripts/toolchain/cgmanifest.json
,.github/workflows/cgmanifest.json
)./LICENSES-AND-NOTICES/SPECS/data/licenses.json
,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON
)*.signatures.json
filessudo make go-tidy-all
andsudo make go-test-coverage
passSummary
Patch kubevirt for CVE-2024-33394
Patch Modified: Yes
manifests/generated/operator-csv.yaml.in
andmanifests/generated/rbac-operator.authorization.k8s.yaml.in
due to version mismatch between existing "kubevirt" and "Astrolabe Patch".Change Log
Does this affect the toolchain?
NO
Links to CVEs
Test Methodology
kubevirt-0.59.0-29.cm2.src.rpm.log