Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for go uplift to 1.22.7 version and have fix for CVE-2024-24790 #331

Closed
smoshiur1237 opened this issue Nov 11, 2024 · 6 comments
Closed

Comments

@smoshiur1237
Copy link

smoshiur1237 commented Nov 11, 2024

We are having a vulnerability report which is related to CVE-2024-24790 and it has critical score. This can be fixed by uplifting go to 1.22.7. We would appreciate if you support the uplift and add the go uplift in your next official release..

@smoshiur1237
Copy link
Author

/cc @AlonaKaplan @phoracek

@phoracek
Copy link
Member

Hi @smoshiur1237, thanks for reporting this. I have posted #332 to bump the version to the latest 1.22.9.

@smoshiur1237
Copy link
Author

Thanks @phoracek , I have left a comment and request to update the docker file in hack folder to change the go version to 1.22.7

@smoshiur1237
Copy link
Author

@phoracek thanks for merging the uplift. May I know when are you going to have a release to add this change? would it be in patch release or in minor release?

@phoracek
Copy link
Member

@smoshiur1237 I will issue a minor release in a second. Minor because the main branch has a new feature in it #322

@phoracek
Copy link
Member

https://github.com/k8snetworkplumbingwg/ovs-cni/releases/tag/v0.35.0 the container images should be published soon too.

I will close this issue now. @smoshiur1237 thanks for reporting it. Please feel free to reopen in case you see this CVE is not resolved in the new build.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants