-
Notifications
You must be signed in to change notification settings - Fork 594
[AutoPR- Security] Patch python3 for CVE-2025-8194 [HIGH] #14443
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[AutoPR- Security] Patch python3 for CVE-2025-8194 [HIGH] #14443
Conversation
/azurepipelines run |
Azure Pipelines successfully started running 1 pipeline(s). |
/azurepipelines run |
Azure Pipelines successfully started running 1 pipeline(s). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Patch Analysis (the patch applies cleanly w.r.t upstream)
- Buddy Build
- patch applied during the build (check
rpm.log
) - patch include an upstream reference
- PR has security tag
@Kanishk-Bansal Looks like the upstream PR has not been merged yet. Could you please monitor and re-add the ready for reviewer label once the fix is merged? You could also reach out to Nikhil (from MSRC) to learn what the final fix is. In the comment section in the upstream PR, there seems to be an ongoing conversation on an alternative backport which suggests they have not fully agreed on the final fix. |
@abadawi591 The PR python/cpython#137171 has been merged, We can go ahead with the patch |
Co-authored-by: Kevin Lockwood <[email protected]> Co-authored-by: Kevin Lockwood <[email protected]> (cherry picked from commit 1be1fe0)
Auto cherry-pick results:
Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=897049&view=results |
Co-authored-by: Kevin Lockwood <[email protected]> Co-authored-by: Kevin Lockwood <[email protected]> (cherry picked from commit 1be1fe0)
Co-authored-by: Kevin Lockwood <[email protected]> Co-authored-by: Kevin Lockwood <[email protected]> (cherry picked from commit 1be1fe0)
Auto Patch python3 for CVE-2025-8194.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner-chatbot/_build/results?buildId=891155&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-static
subpackages, etc.) have had theirRelease
tag incremented../cgmanifest.json
,./toolkit/scripts/toolchain/cgmanifest.json
,.github/workflows/cgmanifest.json
)./LICENSES-AND-NOTICES/SPECS/data/licenses.json
,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON
)*.signatures.json
filessudo make go-tidy-all
andsudo make go-test-coverage
passSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES
Associated issues
Links to CVEs
Test Methodology