[HIGH] Patch glibc for CVE-2026-4046#17075
Conversation
|
/azurepipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
|
/azurepipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
|
Buddy Build has passed ! |
|
|
||
| %changelog | ||
| * Wed Mar 18 2026 Sumit Jena <v-sumitjena@microsoft.com> - 1.43.1-1 | ||
| * Thu May 07 2026 Aditya Singh <v-aditysing@microsoft.com> - 1.43.1-2 |
There was a problem hiding this comment.
These changelog entries seem incorrect. Looks like multiple dates and an additional 0:1.41.4-7 is being added. Also the epoch number is being dropped.
Please investigate.
There should only be one new entry which adds 0:1.43.1-2
There was a problem hiding this comment.
The issue seems to occur because of this PR - https://github.com/microsoft/azurelinux/pull/16227/changes#diff-3a16540d10913456531c6e011d8fd1881d77104bc52c75e26d7a739eee858d3aL176 which got merged with wrong version history.
I have made 3 corrections -
- epoch value has been added in changelog version.
- Sumit's changelog history date has been updated as it was chronologically incorrect.
- I have added my changelog entry, which was removed by Sumit's merged PR.
Updated version numbers in changelog for buildah.spec.
|
Auto cherry-pick results:
Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1121564&view=results |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
glibcfor CVE-2026-4046glibcand manifest files.Change Log
Does this affect the toolchain?
YES
Links to CVEs
Test Methodology