sonic-net / sonic-fips

SONiC FIPS module
Other
0 stars 9 forks source link

Update OpenSSH to 9.2p1-2+deb12u3 to fix CVE-2024-39894 #66

Closed saiarcot895 closed 1 month ago

saiarcot895 commented 1 month ago

Debian's OpenSSH git repo hasn't been updated with the tagged commit for 9.2p1-2+deb12u3, likely because this was a non-maintainer upload. Therefore, get the debdiff between 9.2p1-2+deb12u2 and 9.2p1-2+deb12u3, and apply that patch here, to effectively bump up the source package version to 9.2p1-2+deb12u3.