[High] Patch moby-engine for CVE-2026-61711, CVE-2026-61712, CVE-2026-75593, CVE-2026-17106 - #18643
[High] Patch moby-engine for CVE-2026-61711, CVE-2026-61712, CVE-2026-75593, CVE-2026-17106#18643jykanase wants to merge 5 commits into
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Buddy Build has passed. |
183d92b to
8c2321c
Compare
|
Buddy Build after recent changes. |
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). 1 pipeline(s) were filtered out due to trigger conditions. |
|
Regarding CVE-2026-17106, Shipping only moby/go-archive#45 leaves the package secure but functionally broken for downstream users, so both must go in together. |
b88b26a to
02e589b
Compare
|
Regression in CVE-2026-17106.patch is fixed after recent changes. Patch LGTM. |
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
Patch for CVE-2026-61711, CVE-2026-61712, CVE-2026-75593, CVE-2026-17106
Change Log
Does this affect the toolchain?
No
Associated issues
Links to CVEs
Test Methodology