Skip to content

[202411] Fix 202411 vulnerability#26326

Open
auspham wants to merge 9 commits intosonic-net:202411from
auspham:austinpham/36979761-fix-202411-vulnerability
Open

[202411] Fix 202411 vulnerability#26326
auspham wants to merge 9 commits intosonic-net:202411from
auspham:austinpham/36979761-fix-202411-vulnerability

Conversation

@auspham
Copy link
Copy Markdown
Contributor

@auspham auspham commented Mar 23, 2026

Why I did it

202411 now has various vulnerability from docker-ptf. This PR cherry-pick the following PRs to 202411:

  1. ci: fix s360 security vulnerability #25876
  2. s360: Resolve library vulnerabilty #26161
  3. ci: fix debian security docker-ptf #26242
  4. fix: tornato and natsever security #26459
Work item tracking
  • Microsoft ADO (number only): 36979761

How I did it

How to verify it

Which release branch to backport (provide reason below if selected)

  • 202305
  • 202311
  • 202405
  • 202411
  • 202505
  • 202511

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from 7b64ef9 to 0a82c46 Compare March 23, 2026 03:05
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from 0a82c46 to 2b10b1c Compare March 25, 2026 05:20
@auspham auspham requested a review from xumia as a code owner March 25, 2026 05:20
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from 2b10b1c to 514ca97 Compare March 25, 2026 09:43
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from 514ca97 to b63d97f Compare March 25, 2026 22:36
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from b63d97f to 18f8946 Compare March 26, 2026 03:20
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from 18f8946 to 9a9b2e2 Compare March 26, 2026 05:28
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from 9a9b2e2 to c2c5638 Compare March 26, 2026 10:35
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from c18d7c2 to 82a2afd Compare March 30, 2026 22:07
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from d36005c to 300a869 Compare March 31, 2026 06:32
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from 300a869 to 7dbb5a0 Compare March 31, 2026 10:33
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham
Copy link
Copy Markdown
Contributor Author

auspham commented Mar 31, 2026

Only 1 vulnerability, already installed latest but still have it.


usr/local/bin/gnmic (gobinary)

Total: 2 (UNKNOWN: 0, LOW: 0, MEDIUM: 1, HIGH: 1, CRITICAL: 0)

┌──────────────────────────┬────────────────┬──────────┬────────┬──────────────────────┬───────────────┬──────────────────────────────────────────────────────────────┐
│         Library          │ Vulnerability  │ Severity │ Status │  Installed Version   │ Fixed Version │                            Title                             │
├──────────────────────────┼────────────────┼──────────┼────────┼──────────────────────┼───────────────┼──────────────────────────────────────────────────────────────┤
│ github.com/docker/docker │ CVE-2026-34040 │ HIGH     │ fixed  │ v28.5.2+incompatible │ 29.3.1        │ Moby has AuthZ plugin bypass when provided oversized request │
│                          │                │          │        │                      │               │ bodies                                                       │
│                          │                │          │        │                      │               │ https://avd.aquasec.com/nvd/cve-2026-34040                   │
│                          ├────────────────┼──────────┤        │                      │               ├──────────────────────────────────────────────────────────────┤
│                          │ CVE-2026-33997 │ MEDIUM   │        │                      │               │ Moby has an Off-by-one error in its plugin privilege         │
│                          │                │          │        │                      │               │ validation                                                   │
│                          │                │          │        │                      │               │ https://avd.aquasec.com/nvd/cve-2026-33997                   │
└──────────────────────────┴────────────────┴──────────┴────────┴──────────────────────┴───────────────┴──────────────────────────────────────────────────────────────┘

Copy link
Copy Markdown
Contributor

@kperumalbfn kperumalbfn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@auspham could you update the description with the verified sonic-mgmt tests with this updated docker

@auspham auspham closed this Apr 14, 2026
@auspham auspham reopened this Apr 14, 2026
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from 849dfe7 to 5833859 Compare April 16, 2026 00:13
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

auspham and others added 2 commits April 16, 2026 23:20
Signed-off-by: Austin Pham (agent) <[email protected]>
Cherry-pick e60cdf2 to bring Go 1.25.9, go-jose/v4, otel/sdk,
aws-sdk-go-v2/s3 upgrades and gocloud-patches to 202411 branch.

Co-authored-by: Copilot <[email protected]>
Signed-off-by: Austin Pham (agent) <[email protected]>
@auspham auspham force-pushed the austinpham/36979761-fix-202411-vulnerability branch from e595895 to 6fecfcd Compare April 16, 2026 23:20
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants