-
Notifications
You must be signed in to change notification settings - Fork 596
[AutoPR- Security] Patch libtiff for CVE-2025-9900 [HIGH] #14736
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[AutoPR- Security] Patch libtiff for CVE-2025-9900 [HIGH] #14736
Conversation
/azurepipelines run |
Azure Pipelines successfully started running 1 pipeline(s). |
Buddy Build -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=940386&view=results
![]() |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
moby-runc, prometheus-process-exporter, pygobject3, ostree are known failures.
Patch applies cleanly and builds fine.
LGTM
/azurepipelines run |
Azure Pipelines successfully started running 1 pipeline(s). |
/azurepipelines run |
Azure Pipelines successfully started running 1 pipeline(s). |
(cherry picked from commit f98f349)
Auto cherry-pick results:
Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=944934&view=results |
(cherry picked from commit f98f349)
(cherry picked from commit f98f349)
(cherry picked from commit f98f349)
(cherry picked from commit f98f349)
(cherry picked from commit f98f349)
(cherry picked from commit f98f349)
Auto cherry-pick results:
Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=947585&view=results |
(cherry picked from commit f98f349)
(cherry picked from commit f98f349)
Auto Patch libtiff for CVE-2025-9900.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner-chatbot/_build/results?buildId=940383&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-static
subpackages, etc.) have had theirRelease
tag incremented../cgmanifest.json
,./toolkit/scripts/toolchain/cgmanifest.json
,.github/workflows/cgmanifest.json
)./LICENSES-AND-NOTICES/SPECS/data/licenses.json
,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON
)*.signatures.json
filessudo make go-tidy-all
andsudo make go-test-coverage
passSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology