Skip to content

Commit 16f363d

Browse files
committed
advisories: add advisories for aws-signing-helper
- One advisory also apply to nvidia-k8s-device-plugin. Signed-off-by: Yutong Sun <[email protected]>
1 parent 8c01572 commit 16f363d

File tree

2 files changed

+39
-0
lines changed

2 files changed

+39
-0
lines changed
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
[advisory]
2+
id = "BRSA-leg349bma1kc"
3+
title = "aws-signing-helper CVE-2025-22870"
4+
cve = "CVE-2025-22870"
5+
severity = "moderate"
6+
description = "A flaw was found in aws-signing-helper dependency x/net, where proxy pattern matching can improperly treat an IPv6 zone ID as a hostname component."
7+
8+
[[advisory.products]]
9+
package-name = "aws-signing-helper"
10+
patched-version = "1.6.0"
11+
patched-epoch = "1"
12+
13+
[updateinfo]
14+
author = "yutongsu"
15+
issue-date = 2025-05-15T23:45:19Z
16+
arches = ["aarch64", "x86_64"]
17+
version = "staging"
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
[advisory]
2+
id = "BRSA-newyz3jucdu5"
3+
title = "aws-signing-helper, nvidia-k8s-device-plugin CVE-2024-45338"
4+
cve = "CVE-2024-45338"
5+
severity = "moderate"
6+
description = "A flaw was found in aws-signing-helper and nvidia-k8s-device-plugin dependency x/net which could lead to a denial of service."
7+
8+
[[advisory.products]]
9+
package-name = "aws-signing-helper"
10+
patched-version = "1.6.0"
11+
patched-epoch = "1"
12+
13+
[[advisory.products]]
14+
package-name = "nvidia-k8s-device-plugin"
15+
patched-version = "0.17.1"
16+
patched-epoch = "1"
17+
18+
[updateinfo]
19+
author = "yutongsu"
20+
issue-date = 2025-05-15T23:52:10Z
21+
arches = ["x86_64", "aarch64"]
22+
version = "staging"

0 commit comments

Comments
 (0)