Skip to content

[202211][FRR][CVE] Add FRR patches to fix CVEs: CVE-2022-43681 CVE-2022-40318…#15263

Merged
qiluo-msft merged 2 commits intosonic-net:202211from
DavidZagury:202211-frr_cves_2305
Jun 19, 2023
Merged

[202211][FRR][CVE] Add FRR patches to fix CVEs: CVE-2022-43681 CVE-2022-40318…#15263
qiluo-msft merged 2 commits intosonic-net:202211from
DavidZagury:202211-frr_cves_2305

Conversation

@DavidZagury
Copy link
Copy Markdown
Contributor

@DavidZagury DavidZagury commented May 30, 2023

CVE-2022-40302

Add patches from PRs
FRRouting/frr#12043
FRRouting/frr#12247

Why I did it

To fix CVEs GHSA-x7mf-v6gh-vm4g GHSA-9rqq-99cf-35g5 GHSA-j7hm-p94x-q9pw

Work item tracking
  • Microsoft ADO (number only): 23268946

How I did it

Added patches from the FRR fix PRs

How to verify it

Which release branch to backport (provide reason below if selected)

  • 201811
  • 201911
  • 202006
  • 202012
  • 202106
  • 202111
  • 202205
  • 202211

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

@DavidZagury DavidZagury requested a review from lguohan as a code owner May 30, 2023 10:05
@DavidZagury DavidZagury marked this pull request as draft May 30, 2023 10:05
@DavidZagury DavidZagury marked this pull request as ready for review June 4, 2023 12:07
@StormLiangMS
Copy link
Copy Markdown
Contributor

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@DavidZagury
Copy link
Copy Markdown
Contributor Author

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Commenter does not have sufficient privileges for PR 15263 in repo sonic-net/sonic-buildimage

@DavidZagury
Copy link
Copy Markdown
Contributor Author

/azpw run Azure.sonic-buildimage

@mssonicbld
Copy link
Copy Markdown
Collaborator

/AzurePipelines run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@qiluo-msft qiluo-msft merged commit 72c5562 into sonic-net:202211 Jun 19, 2023
yxieca pushed a commit to yxieca/sonic-buildimage that referenced this pull request Jun 19, 2023
…22-40318… (sonic-net#15263)

… CVE-2022-40302

Add patches from PRs
FRRouting/frr#12043
FRRouting/frr#12247

#### Why I did it
To fix CVEs GHSA-x7mf-v6gh-vm4g GHSA-9rqq-99cf-35g5 GHSA-j7hm-p94x-q9pw

##### Work item tracking
- Microsoft ADO **(number only)**: 23268946

#### How I did it
Added patches from the FRR fix PRs
yxieca added a commit that referenced this pull request Jun 20, 2023
…22-40318… (#15263) (#15537)

… CVE-2022-40302

Add patches from PRs
FRRouting/frr#12043
FRRouting/frr#12247

#### Why I did it
To fix CVEs GHSA-x7mf-v6gh-vm4g GHSA-9rqq-99cf-35g5 GHSA-j7hm-p94x-q9pw

##### Work item tracking
- Microsoft ADO **(number only)**: 23268946

#### How I did it
Added patches from the FRR fix PRs

Co-authored-by: DavidZagury <32644413+DavidZagury@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants