Commit 2ca0308
fix: resolve April 2026 docker-ptf security vulnerabilities
- Upgrade Go toolchain 1.25.8 → 1.25.9 (fixes CVE-2026-32280 through
CVE-2026-32289: stdlib crypto/tls, archive/tar, html/template, os)
- Bump go.opentelemetry.io/otel/sdk v1.40.0 → v1.43.0 in gnmic
(CVE-2026-39883: PATH hijacking via BSD kenv)
- Add github.com/go-jose/go-jose/v4@v4.1.4 to gnmic, gnoic, grpcurl
(CVE-2026-34986: DoS via crafted JSON Web Encryption)
- Bump github.com/docker/docker to latest in gnmic
(CVE-2026-34040: authorization bypass, CVE-2026-33997: privilege
validation bypass during plugin installation)
- Add aws-sdk-go-v2 eventstream/s3 latest to gnmic
(GHSA-xmrv-pmrh-hhx2: DoS via panic in AWS SDK for Go v2)
- Existing apt-get upgrade covers libpng16-16 fix
(CVE-2026-33416: use-after-free, CVE-2026-33636: OOB read/write)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Ubuntu <austinpham@austinpham-dev-vm-2.d4y3nv5wwgfelhhopdxv1tqjld.dx.internal.cloudapp.net>1 parent 339a245 commit 2ca0308
1 file changed
Lines changed: 8 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
112 | 112 | | |
113 | 113 | | |
114 | 114 | | |
115 | | - | |
| 115 | + | |
116 | 116 | | |
117 | 117 | | |
118 | 118 | | |
| |||
125 | 125 | | |
126 | 126 | | |
127 | 127 | | |
| 128 | + | |
128 | 129 | | |
129 | 130 | | |
130 | 131 | | |
131 | 132 | | |
132 | 133 | | |
133 | 134 | | |
| 135 | + | |
134 | 136 | | |
135 | 137 | | |
136 | 138 | | |
| |||
406 | 408 | | |
407 | 409 | | |
408 | 410 | | |
| 411 | + | |
409 | 412 | | |
410 | 413 | | |
411 | 414 | | |
| |||
420 | 423 | | |
421 | 424 | | |
422 | 425 | | |
423 | | - | |
| 426 | + | |
424 | 427 | | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
425 | 431 | | |
426 | 432 | | |
427 | 433 | | |
| |||
0 commit comments