Skip to content

Conversation

@TomSweeneyRedHat
Copy link
Member

@TomSweeneyRedHat TomSweeneyRedHat commented Dec 26, 2025

Bump golang.org/x/crypto to v0.43.0 to fix
GHSA-56w8-48fp-6mgv

Also bump Go to v1.24.* and Buildah to v1.33.14

Fixes: https://issues.redhat.com/browse/RHEL-134788, https://issues.redhat.com/browse/RHEL-130974

[NO NEW TESTS NEEDED]

What type of PR is this?

/kind api-change
/kind bug
/kind cleanup
/kind deprecation
/kind design
/kind documentation
/kind failing-test
/kind feature
/kind flake
/kind other

What this PR does / why we need it:

How to verify it

Which issue(s) this PR fixes:

Special notes for your reviewer:

Does this PR introduce a user-facing change?

None

@TomSweeneyRedHat TomSweeneyRedHat added the No New Tests Allow PR to proceed without adding regression tests label Dec 26, 2025
@dosubot dosubot bot added the size:M This PR changes 30-99 lines, ignoring generated files. label Dec 26, 2025
Bump golang.org/x/crypto to v0.43.0 to fix
CVE-2025-47913

Also bump Go to v1.24.*

Fixes: https://issues.redhat.com/browse/RHEL-134788, https://issues.redhat.com/browse/RHEL-130974

[NO NEW TESTS NEEDED]

Signed-off-by: tomsweeneyredhat <[email protected]>
Bump Buildah to v1.33.14.

Signed-off-by: tomsweeneyredhat <[email protected]>
@TomSweeneyRedHat TomSweeneyRedHat force-pushed the dev/tsweeney/cve-2025-47913-release-1.33 branch from bc5138c to b184a00 Compare December 26, 2025 20:41
In release-1.41, the way the weight was calculates when checking
cpu-shares was changed.  I believe this has been dragged down into
this repository with the changes necessary to bump runc up to a
much higher version.

Signed-off-by: tomsweeneyredhat <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

No New Tests Allow PR to proceed without adding regression tests size:M This PR changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant