Skip to content

Update golang version for telemetry build in sonic-slave-buster to fix CVE-2021-33195#14618

Closed
FengPan-Frank wants to merge 1 commit intosonic-net:201911from
FengPan-Frank:fenpan_201911
Closed

Update golang version for telemetry build in sonic-slave-buster to fix CVE-2021-33195#14618
FengPan-Frank wants to merge 1 commit intosonic-net:201911from
FengPan-Frank:fenpan_201911

Conversation

@FengPan-Frank
Copy link
Copy Markdown
Contributor

Update golang version for telemetry build in sonic-slave-buster to fix CVE-2021-33195

Why I did it

Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format. Now in 202012 branch we're using 1.14.2

Work item tracking
  • Microsoft ADO (17727291):

How I did it

Bump golang version into 1.15.15 which contains corresponding fix.

How to verify it

unit test to do sanity check.

Which release branch to backport (provide reason below if selected)

  • 201811
  • 201911
  • 202006
  • 202012
  • 202106
  • 202111
  • 202205
  • 202211

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

@ganglyu ganglyu self-requested a review April 12, 2023 05:57
@FengPan-Frank
Copy link
Copy Markdown
Contributor Author

Move into #14636 instead

@FengPan-Frank FengPan-Frank deleted the fenpan_201911 branch April 17, 2023 08:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants