-
Notifications
You must be signed in to change notification settings - Fork 9.2k
HADOOP-19747. Switch to at.yawk.lz4:lz4-java:1.10.2 due to CVE-2025-66566 #8122
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
💔 -1 overall
This message was automatically generated. |
a132521 to
fb824b7
Compare
|
💔 -1 overall
This message was automatically generated. |
fb824b7 to
1d431e8
Compare
|
💔 -1 overall
This message was automatically generated. |
LICENSE-binary
Outdated
| hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/checker/TimeoutFuture.java | ||
|
|
||
| at.yawk.lz4:lz4-java:1.9.0 | ||
| at.yawk.lz4:lz4-java:1.10.1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we upgrade to at.yawk.lz4:lz4-java:1.10.2 ?
1d431e8 to
a36bf84
Compare
|
💔 -1 overall
This message was automatically generated. |
|
@pjfanning Thanks for the contribution! Could we backport this to the branch-3.4 branch? |
…6566 (apache#8122) Contributed by PJ Fanning * HADOOP-19747. Switch to at.yawk.lz4:lz4-java:1.10.2 due to CVE-2025-66566 Signed-off-by: Shilun Fan <[email protected]> Update pom.xml
|
@slfan1989 I created #8176 |
Description of PR
Another CVE - CVE-2025-66566.
2nd PR for HADOOP-19747
How was this patch tested?
For code changes:
LICENSE,LICENSE-binary,NOTICE-binaryfiles?