133 Commits

Author SHA1 Message Date
openeuler-ci-bot
dde3668275
!499 [backport]fix CVE-2025-22870
From: @wu-jichao123 
Reviewed-by: @vegbir, @jing-rui 
Signed-off-by: @jing-rui
2025-04-10 12:49:57 +00:00
wujichao
3f82883ffe [backport]fix CVE-2025-22870
Note:In the modification of the original CVE, the net/netip package was used. However, this package is not available in current version.Therefore, the parseIPZone function in the net package is used instead for the fix.
2025-04-09 16:01:32 +08:00
openeuler-ci-bot
d163ee2593
!481 remove 0001-drop-hard-code-cert.patch and modify CVE-2024-45336
From: @wu-jichao123 
Reviewed-by: @hcnbxx 
Signed-off-by: @hcnbxx
2025-02-25 08:11:11 +00:00
wujichao
fced6976d2 remove 0001-drop-hard-code-cert.patch and modify CVE-2024-45336 2025-02-25 15:45:34 +08:00
openeuler-ci-bot
ab6aaad7a5
!476 [Backport]fix CVE-2024-45341 CVE-2024-45336
From: @wu-jichao123 
Reviewed-by: @hcnbxx 
Signed-off-by: @hcnbxx
2025-02-24 02:58:09 +00:00
wujichao
9e80189d85 [Backport]fix CVE-2024-45341 CVE-2024-45336 2025-02-21 14:42:54 +08:00
openeuler-ci-bot
2d98c40fd3
!437 [Backport-20.03-LTS-SP4]fix CVE-2024-34156
From: @fuowang 
Reviewed-by: @hcnbxx 
Signed-off-by: @hcnbxx
2024-11-05 03:50:51 +00:00
wangshuo
535cf6f207 [Backport-20.03-LTS-SP4]fix CVE-2024-34156 2024-11-04 15:10:27 +08:00
openeuler-ci-bot
335a89266d
!410 Fix CVE-2024-34155
From: @roygiteee 
Reviewed-by: @hcnbxx 
Signed-off-by: @hcnbxx
2024-10-09 08:04:24 +00:00
roy
70e8303abb fix CVE-2024-3415. 2024-09-29 19:18:58 +08:00
openeuler-ci-bot
9401afcd60
!405 fix CVE-2024-24791
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2024-08-13 07:18:11 +00:00
hanchao
1ecc75f8af fix CVE-2024-24791 2024-08-13 16:31:28 +08:00
openeuler-ci-bot
3683b5d27d
!382 golang: fix CVE-2024-24789
From: @vegbir 
Reviewed-by: @hcnbxx 
Signed-off-by: @hcnbxx
2024-06-25 06:40:17 +00:00
vegbir
ad6a913b69 golang: fix CVE-2024-24789
Signed-off-by: vegbir <yangjiaqi16@huawei.com>
2024-06-24 22:15:34 +08:00
openeuler-ci-bot
4b11de5887
!362 [sync] PR-361: backport: fix CVE-2024-24787
From: @openeuler-sync-bot 
Reviewed-by: @hcnbxx 
Signed-off-by: @hcnbxx
2024-05-28 03:00:01 +00:00
Lu Jingxiao
6780406796 backport: fix CVE-2024-24787
Signed-off-by: Lu Jingxiao <lujingxiao@huawei.com>
(cherry picked from commit 66a307a0e760e1d099b2ad51cda71a44adc9c530)
2024-05-28 09:23:43 +08:00
openeuler-ci-bot
0715c0df85
!334 backport: fix CVE-2023-45288
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2024-04-17 02:10:49 +00:00
hanchao
2257649bc3 backport: fix CVE-2023-45288 2024-04-16 11:58:08 +08:00
openeuler-ci-bot
61c189b7eb
!323 backport the upstream patch, fix the overflow issue in runtime.netpollWaiters
From: @fuowang 
Reviewed-by: @hcnbxx, @jing-rui 
Signed-off-by: @jing-rui
2024-03-29 02:17:58 +00:00
wangshuo
9b819ac1bf backport the upstream patch, fix the overflow issue in runtime.netpollWaiters 2024-03-28 17:32:39 +08:00
openeuler-ci-bot
9d09ecc926
!320 fix failure of net/http unit test and fix CVE-2024-24784
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2024-03-28 08:37:06 +00:00
hanchao
f4c9675d23 backport: fix CVE-2024-24784 2024-03-28 12:56:17 +08:00
hanchao
579269c1d8 bugfix: fix failure of net/http unit test 2024-03-28 12:54:11 +08:00
openeuler-ci-bot
7619d4c97d
!304 backport:fix CVE-2024-24783,CVE-2024-24785,CVE-2023-45290,CVE-2023-45289
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2024-03-15 08:36:15 +00:00
hanchao
f2859f8a72 backport:fix CVE-2024-24783,CVE-2024-24785,CVE-2023-45290,CVE-2023-45289 2024-03-15 16:32:46 +08:00
openeuler-ci-bot
5dc98a1f35
!294 fix test error about mod_insecure_issue63845
From: @fuowang 
Reviewed-by: @hcnbxx, @jing-rui 
Signed-off-by: @jing-rui
2024-01-16 03:02:43 +00:00
wangshuo
a7a3874295 fix test error about mod_insecure_issue63845 2023-12-27 15:55:16 +08:00
openeuler-ci-bot
0a7e450705
!291 cvefix: fix CVE-2023-39326,CVE-2023-45285
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2023-12-15 12:30:13 +00:00
hanchao
a4aa7eee28 cvefix: fix CVE-2023-39326,CVE-2023-45285 2023-12-15 20:45:38 +08:00
openeuler-ci-bot
0b76401dd9
!279 cvefix: fix CVE-2023-39325
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2023-10-28 09:14:43 +00:00
hanchao
4af3c6fe6d cvefix: fix CVE-2023-39325 2023-10-28 16:41:27 +08:00
openeuler-ci-bot
bed0a15903
!274 cvefix:fix CVE-2023-39323
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2023-10-28 03:42:36 +00:00
luoyujie
cc7f90041b cvefix:fix CVE-2023-39323 2023-10-28 12:55:03 +08:00
openeuler-ci-bot
b70d70b379
!257 [Backport]fix CVE-2023-39318 and CVE-2023-39319
From: @Rose-yujie 
Reviewed-by: @hcnbxx, @jing-rui 
Signed-off-by: @jing-rui
2023-09-27 05:44:53 +00:00
luoyujie
03a29d5388 fix CVE-2023-39318 and CVE-2023-39319 2023-09-25 11:49:03 +08:00
openeuler-ci-bot
8f92f371c3
!254 permit requests with invalid Host headers
From: @ChendongSun 
Reviewed-by: @hcnbxx, @jing-rui 
Signed-off-by: @jing-rui
2023-08-25 08:49:30 +00:00
sunchendong
d9df071cb0 permit requests with invalid Host headers 2023-08-25 15:39:10 +08:00
openeuler-ci-bot
e7dc1121bd
!245 cvefix:fix CVE-2023-29409
From: @Rose-yujie 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2023-08-21 06:26:49 +00:00
luoyujie
ff5bae14ab cvefix:fix CVE-2023-29409 2023-08-18 10:54:19 +08:00
openeuler-ci-bot
a694cee258
!234 cvefix:fix CVE-2023-29406
From: @hcnbxx 
Reviewed-by: @jing-rui, @zhangsong234 
Signed-off-by: @jing-rui
2023-08-07 06:43:16 +00:00
hanchao
d2d2ed93fb cvefix:fix CVE-2023-29406
score:6.5
reference:https://go-review.googlesource.com/c/go/+/507358
2023-07-25 11:31:41 +08:00
openeuler-ci-bot
63f5cda4f1
!218 bugfix: fix build error for go test runtime
From: @hcnbxx 
Reviewed-by: @caihaomin 
Signed-off-by: @caihaomin
2023-07-07 08:45:17 +00:00
hanchao
27c663e5bf bugfix: fix build error for go test runtime 2023-07-07 17:17:03 +08:00
openeuler-ci-bot
ce9d8ab69a
!216 cvefix:fix CVE-2023-29403
From: @hcnbxx 
Reviewed-by: @zhangsong234, @jing-rui 
Signed-off-by: @jing-rui
2023-06-30 01:27:06 +00:00
hanchao
025dbdf1eb cvefix:fix CVE-2023-29403 2023-06-29 20:46:38 +08:00
openeuler-ci-bot
65aa6f00de
!213 cvefix: CVE-2023-29402,CVE-2023-29404,CVE-2023-29405,CVE-2023-29403
From: @hcnbxx 
Reviewed-by: @zhangsong234, @jing-rui 
Signed-off-by: @jing-rui
2023-06-29 01:22:10 +00:00
hanchao
debf83463a cvefix: CVE-2023-29402,CVE-2023-29404,CVE-2023-29405,CVE-2023-29403 2023-06-29 00:03:17 +08:00
openeuler-ci-bot
04742352c3
!203 bugfix: fix CVE-2023-29400,CVE-2023-24539,CVE-2023-24540
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2023-05-23 09:29:21 +00:00
hanchao
2ac3ebbd18 bugfix: fix CVE-2023-29400,CVE-2023-24539,CVE-2023-24540
CVE:CVE-2023-29400,CVE-2023-24539,CVE-2023-24540
Reference:https://go-review.googlesource.com/c/go/+/491615,https://go-review.googlesource.com/c/go/+/491616,https://go-review.googlesource.com/c/go/+/491617
Type:CVE
Reason:fix CVE-2023-29400,CVE-2023-24539,CVE-2023-24540
2023-05-22 23:01:57 +08:00
openeuler-ci-bot
af8ef0f258
!189 golang-1.15: fix a deadlock issue when a signal is received
From: @hcnbxx 
Reviewed-by: @jing-rui 
Signed-off-by: @jing-rui
2023-04-14 09:47:17 +00:00