microsoft / azurelinux

Linux OS for Azure 1P services and edge appliances
MIT License
4.31k stars 553 forks source link

fix CVE-2023-39325, CVE-2023-44487 and CVE-2023-45288 #11200

Closed Xiaohong-Deng closed 2 days ago

Xiaohong-Deng commented 1 week ago
Merge Checklist

All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)


Summary

Fix multus impacted by CVE-2023-39325, CVE-2023-44487 and CVE-2023-45288. Because CVE-2023-39325 is a subset of CVE-2023-44487, there is no patch file for it.

Change Log
Does this affect the toolchain?

NO

Associated issues
Links to CVEs
Test Methodology
CBL-Mariner-Bot commented 2 days ago

Auto cherry-pick results:

Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=684260&view=results