generated from redhat-developer/new-project-template
-
Notifications
You must be signed in to change notification settings - Fork 45
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
chore: release notes for 1.3.4 (#857)
* chore: release notes for 1.3.4 Signed-off-by: Nick Boldt <nboldt@redhat.com> chore: release notes for 1.3.4 Signed-off-by: Nick Boldt <nboldt@redhat.com> * regen release notes Signed-off-by: Nick Boldt <nboldt@redhat.com> * generate node/go CVE list Signed-off-by: Nick Boldt <nboldt@redhat.com> * formatting tweaks + enable one of the 4 RPM CVEs until the other 3 are ready Signed-off-by: Nick Boldt <nboldt@redhat.com> * Update modules/release-notes/list-fixed-security-issues-in-product-1.3.4.txt * Update modules/release-notes/list-fixed-security-issues-in-product-1.3.4.txt * Update modules/release-notes/list-fixed-security-issues-in-product-1.3.4.txt * update RN with more fixed rpm and node/go CVEs; add missing RN item for https://issues.redhat.com/browse/RHIDP-5477 bug fix too Signed-off-by: Nick Boldt <nboldt@redhat.com> * regen from jira using ./modules/release-notes/single-source-release-notes.py script Signed-off-by: Nick Boldt <nboldt@redhat.com> * regen known-issue-rhidp-5342 using ./modules/release-notes/single-source-release-notes.py Signed-off-by: Nick Boldt <nboldt@redhat.com> * apply Lindsey's feedback in JIRA and regenerate Signed-off-by: Nick Boldt <nboldt@redhat.com> --------- Signed-off-by: Nick Boldt <nboldt@redhat.com>
- Loading branch information
Showing
13 changed files
with
433 additions
and
347 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
7 changes: 7 additions & 0 deletions
7
modules/release-notes/list-fixed-security-issues-in-product-1.3.4.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,7 @@ | ||
# done in 1.3.4 | ||
CVE-2024-56201, rhdh-hub-rhel9: Jinja has a sandbox breakout through malicious filenames | ||
CVE-2024-56326, rhdh-hub-rhel9: Jinja has a sandbox breakout through indirect reference to format method | ||
CVE-2024-55565, rhdh-hub-rhel9: nanoid mishandles non-integer values | ||
|
||
CVE-2024-45338, rhdh-rhel9-operator: Non-linear parsing of case-insensitive content in golang.org/x/net/html | ||
CVE-2024-52798, rhdh-hub-rhel9: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x |
14 changes: 14 additions & 0 deletions
14
modules/release-notes/list-fixed-security-issues-in-rpm-1.3.4.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,14 @@ | ||
# https://errata.engineering.redhat.com/advisory/143859 | ||
CVE-2024-9287, python 3.11: Virtual environment (venv) activation scripts don't quote paths | ||
|
||
# https://errata.engineering.redhat.com/advisory/144019, kernel-5.14.0-503.21.1.el9_5 | ||
CVE-2024-46713, kernel: perf/aux: Fix AUX buffer serialization | ||
CVE-2024-50208, kernel: RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages | ||
CVE-2024-50252, kernel: mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address | ||
CVE-2024-53122, kernel: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust | ||
|
||
# https://errata.engineering.redhat.com/advisory/139648, skopeo-1.16.1-2.el9_5 | ||
CVE-2024-34156, encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion | ||
|
||
# https://errata.engineering.redhat.com/advisory/143848, python3.9-3.9.21-1.el9_5 | ||
CVE-2024-11168, python 3.9: Improper validation of IPv6 and IPvFuture addresses |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.