Skip to content

[action] [PR:26676] fix: resolve April 2026 docker-ptf security vulnerabilities#26866

Open
mssonicbld wants to merge 1 commit intosonic-net:202511from
mssonicbld:cherry/202511/26676
Open

[action] [PR:26676] fix: resolve April 2026 docker-ptf security vulnerabilities#26866
mssonicbld wants to merge 1 commit intosonic-net:202511from
mssonicbld:cherry/202511/26676

Conversation

@mssonicbld
Copy link
Copy Markdown
Collaborator

Why I did it

Attempt to fix new docker-ptf security vulnerability as of 04/2026

This pull request updates the dockers/docker-ptf/Dockerfile.j2 to incorporate several dependency upgrades and security improvements. The main focus is on updating Go and related dependencies to address vulnerabilities and ensure compatibility with the latest features and fixes.

Dependency and version updates:

  • Upgraded the Go version used in the Docker image from 1.25.8 to 1.25.9 for improved stability and security.
  • Updated the go.opentelemetry.io/otel/sdk dependency from version v1.40.0 to v1.43.0 for the gnmic build process.
  • Added or updated the github.com/go-jose/go-jose/v4 dependency to version v4.1.4 in the build steps for grpcurl, gnoic, and gnmic to ensure consistent cryptography support. [1] [2] [3]
  • Added the latest versions of github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream and github.com/aws/aws-sdk-go-v2/service/s3 as dependencies for the gnmic build.

Security improvements:

  • Included a system package upgrade step to address vulnerabilities such as CVE-2026-33416 and CVE-2026-33636 (affecting libpng16-16), among others.
Work item tracking
  • Microsoft ADO (number only):

How I did it

How to verify it

Which release branch to backport (provide reason below if selected)

  • 202305
  • 202311
  • 202405
  • 202411
  • 202505
  • 202511

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

Signed-off-by: Sonic Build Admin sonicbld@microsoft.com

A picture of a cute animal (not mandatory but encouraged)

<!--
     Please make sure you've read and understood our contributing guidelines:
     https://github.com/Azure/SONiC/blob/gh-pages/CONTRIBUTING.md

     ** Make sure all your commits include a signature generated with `git commit -s` **

     If this is a bug fix, make sure your description includes "fixes #xxxx", or
     "closes #xxxx" or "resolves #xxxx"

     Please provide the following information:
-->

#### Why I did it
Attempt to fix new docker-ptf security vulnerability as of 04/2026

This pull request updates the `dockers/docker-ptf/Dockerfile.j2` to incorporate several dependency upgrades and security improvements. The main focus is on updating Go and related dependencies to address vulnerabilities and ensure compatibility with the latest features and fixes.

Dependency and version updates:

* Upgraded the Go version used in the Docker image from `1.25.8` to `1.25.9` for improved stability and security.
* Updated the `go.opentelemetry.io/otel/sdk` dependency from version `v1.40.0` to `v1.43.0` for the `gnmic` build process.
* Added or updated the `github.com/go-jose/go-jose/v4` dependency to version `v4.1.4` in the build steps for `grpcurl`, `gnoic`, and `gnmic` to ensure consistent cryptography support. [[1]](diffhunk://#diff-bdead431cfeb50ac3debd09da54bbc77f0b1772edf769de0cd4e30538fd012e0R128-R135) [[2]](diffhunk://#diff-bdead431cfeb50ac3debd09da54bbc77f0b1772edf769de0cd4e30538fd012e0R411) [[3]](diffhunk://#diff-bdead431cfeb50ac3debd09da54bbc77f0b1772edf769de0cd4e30538fd012e0L423-R429)
* Added the latest versions of `github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream` and `github.com/aws/aws-sdk-go-v2/service/s3` as dependencies for the `gnmic` build.

Security improvements:

* Included a system package upgrade step to address vulnerabilities such as CVE-2026-33416 and CVE-2026-33636 (affecting `libpng16-16`), among others.

##### Work item tracking
- Microsoft ADO **(number only)**:

#### How I did it

#### How to verify it

<!--
If PR needs to be backported, then the PR must be tested against the base branch and the earliest backport release branch and provide tested image version on these two branches. For example, if the PR is requested for master, 202211 and 202012, then the requester needs to provide test results on master and 202012.
-->

#### Which release branch to backport (provide reason below if selected)

<!--
- Note we only backport fixes to a release branch, *not* features!
- Please also provide a reason for the backporting below.
- e.g.
- [x] 202006
-->

- [ ] 202305
- [ ] 202311
- [ ] 202405
- [ ] 202411
- [ ] 202505
- [ ] 202511

#### Tested branch (Please provide the tested image version)

<!--
- Please provide tested image version
- e.g.
- [x] 20201231.100
-->

- [ ] <!-- image version 1 -->
- [ ] <!-- image version 2 -->

#### Description for the changelog
<!--
Write a short (one line) summary that describes the changes in this
pull request for inclusion in the changelog:
-->

<!--
 Ensure to add label/tag for the feature raised. example - PR#2174 under sonic-utilities repo. where, Generic Config and Update feature has been labelled as GCU.
-->

#### Link to config_db schema for YANG module changes
<!--
Provide a link to config_db schema for the table for which YANG model
is defined
Link should point to correct section on https://github.com/Azure/sonic-buildimage/blob/master/src/sonic-yang-models/doc/Configuration.md
-->

Signed-off-by: Sonic Build Admin <sonicbld@microsoft.com>

#### A picture of a cute animal (not mandatory but encouraged)
@mssonicbld
Copy link
Copy Markdown
Collaborator Author

Original PR: #26676

@mssonicbld
Copy link
Copy Markdown
Collaborator Author

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant