Skip to content

[Medium] patch rust for CVE-2025-53605#14354

Merged
LeoMar4 merged 3 commits into
microsoft:3.0-devfrom
jykanase:topic_rust-cve-3.0
Aug 12, 2025
Merged

[Medium] patch rust for CVE-2025-53605#14354
LeoMar4 merged 3 commits into
microsoft:3.0-devfrom
jykanase:topic_rust-cve-3.0

Conversation

@jykanase

@jykanase jykanase commented Jul 21, 2025

Copy link
Copy Markdown
Merge Checklist

All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)

  • The toolchain has been rebuilt successfully (or no changes were made to it)
  • The toolchain/worker package manifests are up-to-date
  • Any updated packages successfully build (or no packages were changed)
  • Packages depending on static components modified in this PR (Golang, *-static subpackages, etc.) have had their Release tag incremented.
  • Package tests (%check section) have been verified with RUN_CHECK=y for existing SPEC files, or added to new SPEC files
  • All package sources are available
  • cgmanifest files are up-to-date and sorted (./cgmanifest.json, ./toolkit/scripts/toolchain/cgmanifest.json, .github/workflows/cgmanifest.json)
  • LICENSE-MAP files are up-to-date (./LICENSES-AND-NOTICES/SPECS/data/licenses.json, ./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md, ./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)
  • All source files have up-to-date hashes in the *.signatures.json files
  • sudo make go-tidy-all and sudo make go-test-coverage pass
  • Documentation has been updated to match any changes to the build system
  • Ready to merge

Summary

patch rust for CVE-2025-53605
Patch Modification: No

Change Log
Does this affect the toolchain?

NO

Associated issues
  • #xxxx
Links to CVEs
Test Methodology
  • Verified patches are applied in the pipeline build.
Screenshot 2025-07-21 215346 Screenshot 2025-07-21 215510

@jykanase jykanase requested review from a team as code owners July 21, 2025 12:20
@microsoft-github-policy-service microsoft-github-policy-service Bot added Packaging specs-extended PR to fix SPECS-EXTENDED 3.0-dev PRs Destined for AzureLinux 3.0 labels Jul 21, 2025
@jykanase jykanase marked this pull request as draft July 21, 2025 12:26
@jykanase jykanase force-pushed the topic_rust-cve-3.0 branch from 6ccb228 to a781921 Compare July 22, 2025 04:19
@jykanase jykanase marked this pull request as ready for review July 22, 2025 04:27
@KavyaSree2610

Copy link
Copy Markdown

Please resolve conflicts @jykanase

Comment thread SPECS/rpm-ostree/rpm-ostree.spec Outdated
@jykanase jykanase force-pushed the topic_rust-cve-3.0 branch from a781921 to 2850a7b Compare July 23, 2025 07:21
@KavyaSree2610

Copy link
Copy Markdown

Retriggering the buddy build for SPECS due to a version upgrade in kata-containers
https://dev.azure.com/mariner-org/mariner/_build/results?buildId=877406&view=results

@jykanase

Copy link
Copy Markdown
Author

Please resolve conflicts @jykanase

resolved

@KavyaSree2610

Copy link
Copy Markdown

@KavyaSree2610

KavyaSree2610 commented Jul 24, 2025

Copy link
Copy Markdown

@KavyaSree2610 KavyaSree2610 self-requested a review July 24, 2025 06:05
@suresh-thelkar

Copy link
Copy Markdown

Code changes look good to me. I have also verified that the patch is getting applied successfully through the above full build logs. Here is the screenshot.
image
image

@suresh-thelkar

Copy link
Copy Markdown

I sign-off of the patch changes to be merged into Azure Linux.

@jykanase jykanase force-pushed the topic_rust-cve-3.0 branch from 2850a7b to b1c0730 Compare August 8, 2025 04:23
@Malateshk007

Copy link
Copy Markdown

@LeoMar4 / @0xba1a / @kgodara912 , gentle reminder for review and approval!

@LeoMar4 LeoMar4 merged commit 92fff69 into microsoft:3.0-dev Aug 12, 2025
16 checks passed
SumitJenaHCL pushed a commit to SumitJenaHCL/azurelinux that referenced this pull request Aug 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.0-dev PRs Destined for AzureLinux 3.0 Packaging security specs-extended PR to fix SPECS-EXTENDED

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants