Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cherrypicks Update packages for http v2x/net CVE #3585

Merged
merged 6 commits into from
Nov 8, 2023

Conversation

vyaghras
Copy link
Contributor

@vyaghras vyaghras commented Nov 8, 2023

Description of changes:
Cherry-picks #3581

Testing done:
See #3581

Terms of contribution:

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

This update is required to mitigate HTTP V2 x/net (CVE-2023-39325)

(cherry picked from commit 75fcfc0)
This update is required to mitigate HTTP V2 x/net (CVE-2023-39325)

(cherry picked from commit c336833)
This update is required to mitigate HTTP V2 x/net (CVE-2023-39325)

(cherry picked from commit 16d7307)
This update is required to mitigate HTTP V2 x/net (CVE-2023-39325)

(cherry picked from commit 7719f45)
This update is required to mitigate HTTP V2 x/net (CVE-2023-39325)

(cherry picked from commit 953694c)
pick 821a6417 packages: update ecs-agent to 1.77.0

(cherry picked from commit b69de58)
@vyaghras vyaghras changed the title Cherrypick Update packages for http v2x/net CVE Cherrypicks Update packages for http v2x/net CVE Nov 8, 2023
@vyaghras vyaghras merged commit 60656f8 into bottlerocket-os:1.16.x Nov 8, 2023
@vyaghras vyaghras deleted the http_v2 branch November 8, 2023 20:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants