[Medium] Patch perl for CVE-2026-8376#17591
Conversation
Kanishk-Bansal
left a comment
There was a problem hiding this comment.
(.venv) kanbansal@TDC626371074 [ ~/azurelinux/SPECS/perl ]$ rpmspec -P perl.spec
error: Unable to open /usr/src/azl/SOURCES/gendep.macros: No such file or directory
error: line 145: Unclosed %if
@microsoft-github-policy-service agree company="Microsoft" |
|
Buddy Build has been triggered and it has passed ! |
|
Buddy Build has been re-triggered and it has passed !- https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1131863&view=results |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
Patch perl for CVE-2026-8376
The Upstream patch reference in Astrolabe was incomplete.
Complete patch reference as follows:
PR - CVE-2026-8376: test against the actual character lengths Perl/perl5#24433
Updated spec file to make it parsable when executed using "rpmspec" command.
Change Log
-modified: SPECS/perl/perl.spec
-new: /SPECS/perl/CVE-2026-8376.patch
-modified: toolkit/resources/manifests/package/pkggen_core_x86_64.txt
-modified: toolkit/resources/manifests/package/toolchain_aarch64.txt
-modified: toolkit/resources/manifests/package/toolchain_x86_64.txt
Does this affect the toolchain?
Yes
Links to CVEs
Test Methodology