[AutoPR- Security] Patch rust-afterburn for CVE-2026-25541 [MEDIUM]#16943
[AutoPR- Security] Patch rust-afterburn for CVE-2026-25541 [MEDIUM]#16943azurelinux-security wants to merge 3 commits intomicrosoft:3.0-devfrom
Conversation
|
We added Patch4 because Cargo’s vendored source mechanism includes an integrity file: If we apply Patch3 before untaring %{SOURCE1}, RPM/patch would fail with “file not found” because there would be no vendor/bytes/... files to patch. So the ordering is: Unpack upstream afterburn sources (Source0) |
Auto Patch rust-afterburn for CVE-2026-25541.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1105585&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology