[AutoPR- Security] Patch python3 for CVE-2025-8194 [HIGH]#14443
Conversation
|
/azurepipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
|
/azurepipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
Patch Analysis (the patch applies cleanly w.r.t upstream)
- Buddy Build
- patch applied during the build (check
rpm.log) - patch include an upstream reference
- PR has security tag
|
@Kanishk-Bansal Looks like the upstream PR has not been merged yet. Could you please monitor and re-add the ready for reviewer label once the fix is merged? You could also reach out to Nikhil (from MSRC) to learn what the final fix is. In the comment section in the upstream PR, there seems to be an ongoing conversation on an alternative backport which suggests they have not fully agreed on the final fix. |
|
@abadawi591 The PR python/cpython#137171 has been merged, We can go ahead with the patch |
Co-authored-by: Kevin Lockwood <57274670+kevin-b-lockwood@users.noreply.github.com> Co-authored-by: Kevin Lockwood <v-klockwood@microsoft.com> (cherry picked from commit 1be1fe0)
|
Auto cherry-pick results:
Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=897049&view=results |
Co-authored-by: Kevin Lockwood <57274670+kevin-b-lockwood@users.noreply.github.com> Co-authored-by: Kevin Lockwood <v-klockwood@microsoft.com> (cherry picked from commit 1be1fe0)
Co-authored-by: Kevin Lockwood <57274670+kevin-b-lockwood@users.noreply.github.com> Co-authored-by: Kevin Lockwood <v-klockwood@microsoft.com> (cherry picked from commit 1be1fe0)
Auto Patch python3 for CVE-2025-8194.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner-chatbot/_build/results?buildId=891155&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES
Associated issues
Links to CVEs
Test Methodology