Commit Graph

1527 Commits

Author SHA1 Message Date
Muhammad Falak R Wani ad95d11916
skopeo: upgrade version 1.13.3 -> 1.14.1 to address GHSA-jq35-85cj-fj4p (#7357)
Reference: https://github.com/advisories/GHSA-jq35-85cj-fj4p
Changelog: https://github.com/containers/skopeo/releases/tag/v1.14.1
Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
2024-01-23 08:48:00 +05:30
Aurélien 904fdec443
Introduce Rust virtiofsd package (#7215) 2024-01-19 10:15:09 -08:00
Pawel Winogrodzki 400cedf4b9
Fixed `cloud-init` tests. (#7330)
Co-authored-by: Dan Streetman <ddstreet@ieee.org>
2024-01-19 08:52:47 -08:00
Dallas Delaney babfccfb47
Kata-CC: Upgrade to 0.6.3 (#7196)
Co-authored-by: Aurélien Bombo <abombo@microsoft.com>
Co-authored-by: ms-mahuber <60939654+ms-mahuber@users.noreply.github.com>
Co-authored-by: Mitch Zhu <mitchzhu@microsoft.com>
2024-01-17 13:02:28 -08:00
Gary Swalling 1328babbb5
Kernel upgrade to version 5.15.145.2 (#7280) 2024-01-16 20:23:43 -08:00
Gary Swalling 6e583d646b
Upgrade kernel-mos to 5.15.145.2 (#7227) 2024-01-16 15:21:31 -08:00
Mandeep Plaha cf69f07d13
Upgrade kured to 1.14.2 for vendored go CVE-2023-39325 (#7275) 2024-01-16 13:52:42 -08:00
Dan Streetman 4cfc44fcaa Update sudo to 1.9.15p5 for CVE-2023-42465 2024-01-12 16:20:29 -05:00
CBL-Mariner-Bot 174ad4ca00
[AUTOPATCHER-CORE] Upgrade packer to 1.8.7 CVE-2023-45286 (#7081)
Co-authored-by: Bala <balakumaran.kannan@microsoft.com>
Co-authored-by: Bala <kumaran.4353@gmail.com>
Co-authored-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
2024-01-12 15:31:02 +05:30
Jon Slobodzian c9da0704ef Revert "Upgrade kernel-mos to 5.15.143.1 (#7086)"
This reverts commit 5324a3a344.
2024-01-11 05:30:41 -08:00
Jon Slobodzian 1a57d91875 Revert "fix: upgrade cloud-init to v23.4.1 (#7065)"
This reverts commit fc07dc5399.
2024-01-10 17:16:48 -08:00
rlmenge 478618d56f
Revert "[AUTOPATCHER-kernel] Kernel upgrade to version 5.15.143.1 - branch main (#7048)" (#7222) 2024-01-10 15:57:39 -08:00
CBL-Mariner-Bot 9d61e77566
[AUTOPATCHER-kernel] Kernel upgrade to version 5.15.145.1 - branch main (#7156) 2024-01-08 12:52:47 -08:00
sindhu-karri 9eb66b6101
Upgrade and move libdwarf from extended to core (#6827) 2024-01-05 14:08:24 +05:30
Neha Agarwal c00ee1fff4
libssh: update to v0.10.6 to fix CVE-2023-48795 (#7141) 2024-01-02 09:41:59 -08:00
Neha Agarwal a3d7868c0c
postgresql: update to v14.10 to fix CVE-2023-5868, CVE-2023-5869 and CVE-2023-5870 (#7138) 2023-12-29 13:11:23 -08:00
Neha Agarwal f2a17384db
dbus: Update to v1.15.6 to fix CVE-2023-34969 (#7134) 2023-12-29 10:43:02 -08:00
Neha Agarwal 46d5a680f5
ansible: update to v2.14.12 to fix CVE-2023-5764 (#7124) 2023-12-26 11:38:03 -08:00
Christopher Co fc07dc5399
fix: upgrade cloud-init to v23.4.1 (#7065)
This change upgrades cloud-init to v23.4.1. This version contains fixes for an issue where some Azure Stack implementations do not support IMDS. Also this cloud-init version has the override data source patch integrated so we can drop the patch from our packaging.

Signed-off-by: Chris Co <chrco@microsoft.com>
2023-12-22 22:50:49 -08:00
Gary Swalling 5324a3a344
Upgrade kernel-mos to 5.15.143.1 (#7086) 2023-12-21 11:40:37 -08:00
CBL-Mariner-Bot b1ffd4eeb3
[AUTOPATCHER-kernel] Kernel upgrade to version 5.15.143.1 - branch main (#7048)
Note this upgrade also required an update to the kernel-hci patches.

Co-authored-by: Vince Perri <viperri@microsoft.com>
2023-12-21 11:11:19 -08:00
CBL-Mariner-Bot 32572206ca
[AUTOPATCHER-CORE] Upgrade fish to 3.6.2 CVE-2023-49284 (#7039) 2023-12-21 09:55:36 +05:30
sindhu-karri c989846a40
Add moreutils package to mariner (#7017) 2023-12-21 08:18:07 +05:30
Rohit Rawat e87fb99c84
Fix CVE-2020-8694, CVE-2020-8695 and CVE-2020-12912 (#7029)
Fixes moby-engine and moby-containerd by upgrade
2023-12-20 20:40:33 +05:30
sindhu-karri 1eec67c797
Add package perl-Time-Duration to mariner (#7016) 2023-12-20 13:12:02 +05:30
CBL-Mariner-Bot 311df2a641
[AUTOPATCHER-CORE] Upgrade curl to 8.5.0 CVE-2023-46219 (#7059)
Co-authored-by: Cameron Baird <cameronbaird@microsoft.com>
2023-12-19 14:37:17 -08:00
sindhu-karri eb04937dc1
Add quotatool package to Mariner (#6995) 2023-12-15 17:15:08 +05:30
rlmenge 859c65b771
Upgrade kernel-mos to 5.15.139.1 (#6984) 2023-12-12 16:54:06 -08:00
Andrew Phelps a9feb53d24
[2.0] libgcrypt: upgrade to 1.10.3 (#6982) 2023-12-12 10:51:03 -08:00
osamaesmailmsft 67e021d3b4
Upgrade Telegraf to 1.28.5 (#6953) 2023-12-08 11:55:42 -08:00
CBL-Mariner-Bot fdf20f7e6f
[AUTO-CHERRYPICK] Upgrade helm to version 3.13.2 - branch main (#6924)
Co-authored-by: sindhu-karri <33163197+sindhu-karri@users.noreply.github.com>
2023-12-07 22:52:44 +05:30
CBL-Mariner-Bot 8c123fd590
[AUTO-CHERRYPICK] Fix CVE 2023 5528 by upgrading kubernetes to version 1.28.4 - branch main (#6929)
Co-authored-by: aadhar-agarwal <108542189+aadhar-agarwal@users.noreply.github.com>
2023-12-06 16:09:20 -08:00
CBL-Mariner-Bot baa125d890
[AUTOPATCHER-kernel] Kernel upgrade to version 5.15.139.1 - branch main (#6909) 2023-12-05 14:40:34 -08:00
CBL-Mariner-Bot 15cf22e02f
[AUTOPATCHER-CORE] Upgrade vim to 9.0.2121 Fix CVE-2023-48706 (#6914) 2023-12-05 12:47:41 -08:00
Trung 1a80468e37
Bump gevent version to 21.1.2, add fix for CVE-2020-22217 (#6887) 2023-12-04 21:24:59 -08:00
ashruti-msft 4341e43e44
Upgrade Blobfuse2 to 2.1.2 (#6803)
Co-authored-by: Anubhuti Shruti <ashruti-msft>
2023-11-30 09:39:32 -05:00
Pawel Winogrodzki 6c7594bc5d
Added package `python3-junit-xml`. (#6812) 2023-11-28 11:15:13 -08:00
CBL-Mariner-Bot 37d627fabc
[AUTOPATCHER-CORE] Upgrade mysql to 8.0.35 none (#6856)
Resolved the following CVEs: CVE-2023-22078, CVE-2023-22068, CVE-2023-22084, CVE-2023-22070, CVE-2023-22092, CVE-2023-22079, CVE-2023-22032, CVE-2023-22103, CVE-2023-22112, CVE-2023-22059, CVE-2023-22114, CVE-2023-22097, CVE-2023-22064, CVE-2023-22066
2023-11-28 10:40:09 -08:00
CBL-Mariner-Bot ef7b051bff
[AUTOPATCHER-CORE] Upgrade vim to 9.0.2112 CVEs (#6852)
Upgraded vim to 9.0.2112 to resolve CVE-2023-48235, CVE-2023-48233, CVE-2023-48232, CVE-2023-48236, CVE-2023-48237, CVE-2023-48234, CVE-2023-48231
2023-11-28 08:53:26 -08:00
sindhu-karri 7f29342f00
Add package double-conversion to SPECS (#6825) 2023-11-27 20:32:51 +05:30
Harshit Gupta 40e7cbcbe5
Add linuxptp v3.1.1 with High-Availability patches (#6404)
Co-authored-by: Harshit Gupta <guptaharshit@microsoft.com>
2023-11-23 11:59:17 -05:00
Andrew Phelps cb07ddc215
msft-golang: upgrade 1.20.11 (#6831) 2023-11-22 14:36:56 -08:00
CBL-Mariner-Bot 06e3445041
[AUTO-CHERRYPICK] Added patch for CVE-2023-46136 to python-werkzeug - branch main (#6802)
Co-authored-by: Nick Samson <nick.samson@microsoft.com>
2023-11-22 10:24:51 -08:00
CBL-Mariner-Bot 61704d6154
[AUTOPATCHER-kernel] Kernel upgrade to version 5.15.138.1 - branch main (#6820) 2023-11-21 13:35:19 -08:00
Sriram Nambakam 9ba4e8f5cf
Upgrade valgrind to 3.22.0 (#6777) 2023-11-16 18:40:33 -08:00
Tobias Brick 9dc4183cf8
fix tmux crashing bug (#6766)
Co-authored-by: Henry Beberman <henry.beberman@microsoft.com>

Fixes issue #6598 which is a crash on selection in tmux. The fix requires an update to ncurses and a patch to tmux. From the patch comments:

```
ncurses-6.4-20230408 change tparm to require cur_term, which broke tmux usage of it.

ncurses-6.4-20230423 then added tiparm_s that allows usage without cur_term.

tmux change 39d41d0810 uses tiparm_s if it exists, but cannot be cleanly applied to tmux tag 3.2a.

That change uses a config setting to created #defines to determine which version of tparm it should use, and only conditionally uses tiparm_s, because it needs to be backwards compatible with previous versions of ncurses.

But to use that, we would need to get the actual source as it appears in github, rather than the released version (they are different downloads: see https://github.com/tmux/tmux/releases).

Fortunately, we have the luxery of forcing tmux to use a version of ncurses that has the function we want (see above).

Given all this, this patch takes the change to use tiparm_s, removes the conditional compilation portion so it always uses tiparm_s and applies it to the code as it exists in 3.2a.

It has both a build-time and run-time dependency on ncurses-6.4-20230423 or later.
```
2023-11-16 11:49:58 -08:00
CBL-Mariner-Bot e47df523d1
[AUTOPATCHER-CORE] Upgrade vim to 9.0.2068 CVE-2023-46246 (#6758) 2023-11-15 13:22:34 -08:00
rlmenge 18dd756586
Add kernel-mos with AMDGPU drivers (#6714)
This change introduces a new x86_64 kernel, kernel-mos, for the purpose of offering a kernel which has newer drivers available then those offered in 5.15 LTS. These newer drivers include newer AMDGPU drivers. This change does not provide an ARM64 kernel.

Kernel-mos pulls from a different source than the generic kernel RPM. The kernel-mos RPM uses the rolling-lts/mariner-2-mos/5.15.y.w tag which contains the additional feature branch for amdgpu drivers.

The kernel-mos.spec also introduces the following subpackages:

kernel-mos-devel: includes the source needed to build kernel-level software
kernel-mos-drivers-accessibility: contains drivers under accessibility
kernel-mos-drivers-gpu: contains drivers under gpu (including amdgpu)
kernel-mos-drivers-sound: contains drivers under sound
kernel-mos-docs: contains the kernel docs
kernel-mos-tools: common linux tools such as cpufreq
kernel-mos-python3-perf: contains the python perf tools
kernel-mos-bpftool: contains bpftool used to inspect btf data

Kernel-mos-signed.spec is also being introduced to allow for signing of the kernel to enable secureboot.
2023-11-14 08:55:00 -08:00
CBL-Mariner-Bot b7cac8052e
[AUTO-CHERRYPICK] Patched `telegraf` CVE-2023-46129. - branch main (#6743)
Co-authored-by: Pawel Winogrodzki <pawelwi@microsoft.com>
2023-11-13 10:09:32 -08:00
CBL-Mariner-Bot aa9e543b4e
[AUTO-CHERRYPICK] Upgrade memcached to v1.6.22: Fixes CVEs 2023-46852 and 2023-46853 - branch main (#6726)
Co-authored-by: Harshit Gupta <harshitgupta1337@gmail.com>
2023-11-13 12:40:45 -05:00