Skip to content

Commit e5afaac

Browse files
[AUTOPATCHER-CORE] Upgrade krb5 to 1.21.3 CVE-2024-37371, CVE-2024-37370 (#9921)
Co-authored-by: Adit Jha <aditjha@microsoft.com>
1 parent acf2b37 commit e5afaac

8 files changed

Lines changed: 19 additions & 80 deletions

File tree

SPECS/krb5/CVE-2023-36054.patch

Lines changed: 0 additions & 62 deletions
This file was deleted.

SPECS/krb5/krb5.signatures.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"Signatures": {
33
"krb5.conf": "54ce761ea22e55923f4b10b5a8ed306f98c579217b4253163437c33eec243720",
4-
"krb5-1.19.4.tar.gz": "41f5981c5a4de0a26b3937e679a116cd5b3739641fd253124aac91f7179b54eb"
4+
"krb5-1.21.3.tar.gz": "b7a4cd5ead67fb08b980b21abd150ff7217e85ea320c9ed0c6dadd304840ad35"
55
}
6-
}
6+
}

SPECS/krb5/krb5.spec

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,15 @@
33

44
Summary: The Kerberos newtork authentication system
55
Name: krb5
6-
Version: 1.19.4
7-
Release: 2%{?dist}
6+
Version: 1.21.3
7+
Release: 1%{?dist}
88
License: MIT
99
Vendor: Microsoft Corporation
1010
Distribution: Mariner
1111
Group: System Environment/Security
1212
URL: https://web.mit.edu/kerberos/
1313
Source0: https://kerberos.org/dist/%{name}/%{maj_version}/%{name}-%{version}.tar.gz
1414
Source1: krb5.conf
15-
Patch0: CVE-2023-36054.patch
1615
BuildRequires: e2fsprogs-devel
1716
BuildRequires: openssl-devel
1817
Requires: e2fsprogs-libs
@@ -45,7 +44,6 @@ These are the additional language files of krb5.
4544

4645
%build
4746
cd src
48-
sed -e 's@\^u}@^u cols 300}@' -i tests/dejagnu/config/default.exp
4947
CPPFLAGS="-D_GNU_SOURCE %{getenv:CPPFLAGS}" \
5048
autoconf &&
5149
./configure \
@@ -127,6 +125,9 @@ make check
127125
%{_datarootdir}/locale/*
128126

129127
%changelog
128+
* Wed Jul 24 2024 CBL-Mariner Servicing Account <cblmargh@microsoft.com> - 1.21.3-1
129+
- Auto-upgrade to 1.21.3 - CVE-2024-37371, CVE-2024-37370
130+
130131
* Mon Aug 21 2023 Tobias Brick <tobiasb@microsoft.com> - 1.19.4-2
131132
- Add patch for CVE-2023-36054
132133

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8351,8 +8351,8 @@
83518351
"type": "other",
83528352
"other": {
83538353
"name": "krb5",
8354-
"version": "1.19.4",
8355-
"downloadUrl": "https://kerberos.org/dist/krb5/1.19/krb5-1.19.4.tar.gz"
8354+
"version": "1.21.3",
8355+
"downloadUrl": "https://kerberos.org/dist/krb5/1.21/krb5-1.21.3.tar.gz"
83568356
}
83578357
}
83588358
},

toolkit/resources/manifests/package/pkggen_core_aarch64.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -188,7 +188,7 @@ libsolv-0.7.24-1.cm2.aarch64.rpm
188188
libsolv-devel-0.7.24-1.cm2.aarch64.rpm
189189
libssh2-1.9.0-4.cm2.aarch64.rpm
190190
libssh2-devel-1.9.0-4.cm2.aarch64.rpm
191-
krb5-1.19.4-2.cm2.aarch64.rpm
191+
krb5-1.21.3-1.cm2.aarch64.rpm
192192
nghttp2-1.57.0-1.cm2.aarch64.rpm
193193
curl-8.5.0-2.cm2.aarch64.rpm
194194
curl-devel-8.5.0-2.cm2.aarch64.rpm

toolkit/resources/manifests/package/pkggen_core_x86_64.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -188,7 +188,7 @@ libsolv-0.7.24-1.cm2.x86_64.rpm
188188
libsolv-devel-0.7.24-1.cm2.x86_64.rpm
189189
libssh2-1.9.0-4.cm2.x86_64.rpm
190190
libssh2-devel-1.9.0-4.cm2.x86_64.rpm
191-
krb5-1.19.4-2.cm2.x86_64.rpm
191+
krb5-1.21.3-1.cm2.x86_64.rpm
192192
nghttp2-1.57.0-1.cm2.x86_64.rpm
193193
curl-8.5.0-2.cm2.x86_64.rpm
194194
curl-devel-8.5.0-2.cm2.x86_64.rpm

toolkit/resources/manifests/package/toolchain_aarch64.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -140,10 +140,10 @@ kernel-headers-5.15.162.2-1.cm2.noarch.rpm
140140
kmod-29-2.cm2.aarch64.rpm
141141
kmod-debuginfo-29-2.cm2.aarch64.rpm
142142
kmod-devel-29-2.cm2.aarch64.rpm
143-
krb5-1.19.4-2.cm2.aarch64.rpm
144-
krb5-debuginfo-1.19.4-2.cm2.aarch64.rpm
145-
krb5-devel-1.19.4-2.cm2.aarch64.rpm
146-
krb5-lang-1.19.4-2.cm2.aarch64.rpm
143+
krb5-1.21.3-1.cm2.aarch64.rpm
144+
krb5-debuginfo-1.21.3-1.cm2.aarch64.rpm
145+
krb5-devel-1.21.3-1.cm2.aarch64.rpm
146+
krb5-lang-1.21.3-1.cm2.aarch64.rpm
147147
libarchive-3.6.1-3.cm2.aarch64.rpm
148148
libarchive-debuginfo-3.6.1-3.cm2.aarch64.rpm
149149
libarchive-devel-3.6.1-3.cm2.aarch64.rpm

toolkit/resources/manifests/package/toolchain_x86_64.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -146,10 +146,10 @@ kernel-headers-5.15.162.2-1.cm2.noarch.rpm
146146
kmod-29-2.cm2.x86_64.rpm
147147
kmod-debuginfo-29-2.cm2.x86_64.rpm
148148
kmod-devel-29-2.cm2.x86_64.rpm
149-
krb5-1.19.4-2.cm2.x86_64.rpm
150-
krb5-debuginfo-1.19.4-2.cm2.x86_64.rpm
151-
krb5-devel-1.19.4-2.cm2.x86_64.rpm
152-
krb5-lang-1.19.4-2.cm2.x86_64.rpm
149+
krb5-1.21.3-1.cm2.x86_64.rpm
150+
krb5-debuginfo-1.21.3-1.cm2.x86_64.rpm
151+
krb5-devel-1.21.3-1.cm2.x86_64.rpm
152+
krb5-lang-1.21.3-1.cm2.x86_64.rpm
153153
libarchive-3.6.1-3.cm2.x86_64.rpm
154154
libarchive-debuginfo-3.6.1-3.cm2.x86_64.rpm
155155
libarchive-devel-3.6.1-3.cm2.x86_64.rpm

0 commit comments

Comments
 (0)