Upgrade valkey to 8.0.6 for CVE-2025-49844 CVE-2025-46817 CVE-2025-46818 CVE-2025-46819#14835
Conversation
…818 CVE-2025-46819 Signed-off-by: Kanishk Bansal <kanbansal@microsoft.com>
06105fa to
ad54660
Compare
| Group: Applications/Databases | ||
| URL: https://valkey.io/ | ||
| Source0: https://github.com/valkey-io/valkey/archive/refs/tags/%{version}.tar.gz#/%{name}-%{version}.tar.gz | ||
| Patch0: valkey-conf.patch |
There was a problem hiding this comment.
valkey-conf.patch is incorporated in 8.0.6
| Source0: https://github.com/valkey-io/valkey/archive/refs/tags/%{version}.tar.gz#/%{name}-%{version}.tar.gz | ||
| Patch0: valkey-conf.patch | ||
| Patch1: disable-mem-defrag-tests.patch | ||
| Patch2: CVE-2025-49112.patch |
There was a problem hiding this comment.
This patch is fixed in 8.0.6 with valkey-io/valkey#2101
| Patch0: valkey-conf.patch | ||
| Patch1: disable-mem-defrag-tests.patch | ||
| Patch2: CVE-2025-49112.patch | ||
| Patch3: CVE-2025-27151.patch |
There was a problem hiding this comment.
This is also fixed by valkey-io/valkey#2146 in 8.0.6
valkey-io/valkey@8.0.4...8.0.6
| Patch1: disable-mem-defrag-tests.patch | ||
| Patch2: CVE-2025-49112.patch | ||
| Patch3: CVE-2025-27151.patch | ||
| Patch0: disable-mem-defrag-tests.patch |
There was a problem hiding this comment.
modified some hunks
|
Valkey 8.0.6 Security fixes Bug fixes |
|
Buddy Build url is wrong @Kanishk-Bansal |
|
Auto cherry-pick results: Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=949126&view=results |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassDoes this affect the toolchain?
YES/NO
Associated issues
Summary
What does the PR accomplish, why was it needed?
Total CVEs processed: 4
Change Log
Links to CVEs
Test Methodology