Skip to content

[202012] Update golang version for telemetry build in sonic-slave-buster to fix CVE-2021-33195#14855

Closed
FengPan-Frank wants to merge 1 commit intosonic-net:202012from
FengPan-Frank:202012cherrypick
Closed

[202012] Update golang version for telemetry build in sonic-slave-buster to fix CVE-2021-33195#14855
FengPan-Frank wants to merge 1 commit intosonic-net:202012from
FengPan-Frank:202012cherrypick

Conversation

@FengPan-Frank
Copy link
Copy Markdown
Contributor

Why I did it

Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format. Now in 202012 branch we're using 1.14.2

Work item tracking
  • Microsoft ADO (number only):17727291

How I did it

Bump golang version into 1.15.15 which contains corresponding fix.

How to verify it

unit test to do sanity check.

Which release branch to backport (provide reason below if selected)

  • 201811
  • 201911
  • 202006
  • 202012
  • 202106
  • 202111
  • 202205
  • 202211

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

@FengPan-Frank
Copy link
Copy Markdown
Contributor Author

@qiluo-msft cherrypick to 202012 branch of #14637 has conflict, I made new PR for 202012 branch merge, please help to review, thanks.

@FengPan-Frank FengPan-Frank changed the title Update golang version for telemetry build in sonic-slave-buster to fix CVE-2021-33195 [202012] Update golang version for telemetry build in sonic-slave-buster to fix CVE-2021-33195 Apr 27, 2023
@FengPan-Frank
Copy link
Copy Markdown
Contributor Author

We decided not to cover the change in 202012 branch, thus this manual cherrypick is not required any more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant