Skip to content

[AUTO-CHERRYPICK] [AutoPR- Security] Patch libsoup for CVE-2025-4948 [HIGH] - branch 3.0-dev #14467

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: 3.0-dev
Choose a base branch
from

Conversation

CBL-Mariner-Bot
Copy link
Collaborator

This is an auto-generated pull request to cherry-pick commit 8faae7f to 3.0-dev. Original PR: #14412

Co-authored-by: kgodara912 <[email protected]>
Co-authored-by: carlapgavilan <[email protected]>
Co-authored-by: Pawel Winogrodzki <[email protected]>
(cherry picked from commit 8faae7f)
@CBL-Mariner-Bot CBL-Mariner-Bot requested a review from a team as a code owner August 8, 2025 21:51
@CBL-Mariner-Bot CBL-Mariner-Bot added the Auto Fast-track Cherry-pick Automatic cherry-pick from fast-track branch label Aug 8, 2025
@CBL-Mariner-Bot
Copy link
Collaborator Author

✅ PR Check Passed

No critical issues detected in spec file changes.

🤖 AI Analysis Summary:

Brief Analysis:
The changes add a new CVE patch (CVE-2025-4948) that fixes an integer underflow risk in multipart body processing. The spec file has been updated with a sequential patch reference and an appropriate changelog entry.

Critical Issues Found:
• No ERROR/CRITICAL issues found.

Recommended Actions:
• Confirm that the newly added CVE-2025-4948.patch file is properly maintained upstream.
• Ensure that the automated patch application via %autosetup -p1 is verified during builds.
• Continue to match changelog CVE references with patch file names for future security patches.


📋 For detailed analysis and recommendations, check the Azure DevOps pipeline logs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3.0-dev PRs Destined for AzureLinux 3.0 Auto Fast-track Cherry-pick Automatic cherry-pick from fast-track branch Automatic PR Packaging
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants