microsoft / azurelinux

Linux OS for Azure 1P services and edge appliances
MIT License
4.08k stars 498 forks source link

libarchive: Patch CVEs 2024-26256 and 2024-37407 #9504

Closed neha170 closed 1 week ago

neha170 commented 1 week ago
Merge Checklist

All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)


Summary

update libarchive to v3.7.4 to fix CVEs 2024-26256 and 2024-37407

Change Log
Does this affect the toolchain?

YES

Links to CVEs
Test Methodology
PawelWMS commented 1 week ago

@neha170, could you also add a link to a buddy build? Or it doesn't build correctly, because it's a toolchain package?