Skip to content

[v25.3.x] build/deps: upgrade krb5 to 1.22.2#30875

Merged
tyson-redpanda merged 2 commits into
v25.3.xfrom
snyk/cve-2026-40355-krb5-1.22.2-v25.3.x
Jun 23, 2026
Merged

[v25.3.x] build/deps: upgrade krb5 to 1.22.2#30875
tyson-redpanda merged 2 commits into
v25.3.xfrom
snyk/cve-2026-40355-krb5-1.22.2-v25.3.x

Conversation

@tyson-redpanda

Copy link
Copy Markdown
Contributor

Upgrades krb5 from 1.21.3 to 1.22.2 on the v25.3.x branch to address CVE-2026-40355 and CVE-2026-40356 (NegoEx parsing vulnerabilities). The memory leak fixes previously applied via 0001 patch are included in 1.22.x upstream, so that patch is dropped. The NegoEx CVE patches still apply cleanly to 1.22.2 and are retained.

Backport of PR #30628

Backports Required

  • none - not a bug fix
  • none - this is a backport
  • none - issue does not exist in previous branches
  • none - papercut/not impactful enough to backport
  • v25.3.x
  • v25.2.x
  • v25.1.x

Release Notes

Bug Fixes

FIXES=CORE-16460
FIXES=CORE-16461

The memory leak fixes from 0001-Fix-two-unlikely-memory-leaks.patch are
included upstream in 1.22.x, so that patch is dropped. The NegoEx CVE
patches (CVE-2026-40355, CVE-2026-40356) apply cleanly to 1.22.2 and
are retained.
@tyson-redpanda tyson-redpanda marked this pull request as ready for review June 23, 2026 14:35
@tyson-redpanda tyson-redpanda enabled auto-merge June 23, 2026 14:35
@vbotbuildovich

Copy link
Copy Markdown
Collaborator

CI test results

test results on build#86153
test_status test_class test_method test_arguments test_kind job_url passed reason test_history
FLAKY(PASS) PartitionReassignmentsTest test_reassignments_cancel null integration https://buildkite.com/redpanda/redpanda/builds/86153#019ef501-0eb3-45c0-8292-ad199a74e15e 9/11 Test PASSES after retries.No significant increase in flaky rate(baseline=0.0625, p0=0.4755, reject_threshold=0.0100. adj_baseline=0.1760, p1=0.4524, trust_threshold=0.5000) https://redpanda.metabaseapp.com/dashboard/87-tests?tab=142-dt-individual-test-history&test_class=PartitionReassignmentsTest&test_method=test_reassignments_cancel
FLAKY(PASS) TxAtomicProduceConsumeTest test_basic_tx_consumer_transform_produce {"with_failures": true} integration https://buildkite.com/redpanda/redpanda/builds/86153#019ef503-f6b6-4352-b960-056ec495e9d5 10/11 Test PASSES after retries.No significant increase in flaky rate(baseline=0.0000, p0=1.0000, reject_threshold=0.0100. adj_baseline=0.1000, p1=0.3487, trust_threshold=0.5000) https://redpanda.metabaseapp.com/dashboard/87-tests?tab=142-dt-individual-test-history&test_class=TxAtomicProduceConsumeTest&test_method=test_basic_tx_consumer_transform_produce

@tyson-redpanda tyson-redpanda requested a review from dotnwat June 23, 2026 16:57
@tyson-redpanda tyson-redpanda merged commit b98478b into v25.3.x Jun 23, 2026
16 checks passed
@tyson-redpanda tyson-redpanda deleted the snyk/cve-2026-40355-krb5-1.22.2-v25.3.x branch June 23, 2026 17:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants