Skip to content

Conversation

@CBL-Mariner-Bot
Copy link
Collaborator

[AUTOPATCHER-CORE] Upgrade net-snmp to 5.9.5 for CVE-2025-68615
Upgrade pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1011154&view=results

Copy link
Collaborator

@jslobodzian jslobodzian left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

build failed:
time="2025-12-23T14:35:16Z" level=debug msg="ERROR:"
time="2025-12-23T14:35:16Z" level=debug msg="Net-SNMP installed version: 5.9.4 => 5.0904"
time="2025-12-23T14:35:16Z" level=debug msg="Perl Module Version: 5.0905"
time="2025-12-23T14:35:16Z" level=debug
time="2025-12-23T14:35:16Z" level=debug msg="These versions must match for perfect support of the module. It is possible"
time="2025-12-23T14:35:16Z" level=debug msg="that different versions may work together, but it is strongly recommended"
time="2025-12-23T14:35:16Z" level=debug msg="that you make these two versions identical. You can get the Net-SNMP"
time="2025-12-23T14:35:16Z" level=debug msg="source code and the associated perl modules directly from"
time="2025-12-23T14:35:16Z" level=debug
time="2025-12-23T14:35:16Z" level=debug msg=" http://www.net-snmp.org/"
time="2025-12-23T14:35:16Z" level=debug
time="2025-12-23T14:35:16Z" level=debug msg="If you want to continue anyway please set the NETSNMP_DONT_CHECK_VERSION"
time="2025-12-23T14:35:16Z" level=debug msg="environmental variable to 1 and re-run the Makefile.PL script."
time="2025-12-23T14:35:16Z" level=debug msg="make: *** [Makefile:308: perl/Makefile] Error 1"
time="2025-12-23T14:35:16Z" level=debug
time="2025-12-23T14:35:16Z" level=debug msg="error: Bad exit status from /var/tmp/rpm-tmp.BJN6Su (%build)"
time="2025-12-23T14:35:16Z" level=debug msg=" bogus date in %changelog: Fri Apr 07 2022 Minghe Ren mingheren@microsoft.com - 5.9.1-2"
time="2025-12-23T14:35:16Z" level=debug msg=" Could not canonicalize hostname: 6a90ad51c000000"
time="2025-12-23T14:35:16Z" level=debug msg=" Bad exit status from /var/tmp/rpm-tmp.BJN6Su (%build)"
time="2025-12-23T14:35:16Z" level=debug msg="RPM build warnings:"
time="2025-12-23T14:35:16Z" level=debug

Signed-off-by: Kanishk Bansal <kanbansal@microsoft.com>
@Kanishk-Bansal Kanishk-Bansal force-pushed the cblmargh/net-snmp-upgrade-to-5.9.5-fasttrack/2.0 branch from 123d0a2 to 6c7a833 Compare December 23, 2025 17:49
@Kanishk-Bansal
Copy link
Contributor

Buddy Build

@Kanishk-Bansal Kanishk-Bansal changed the title [AUTOPATCHER-CORE] Upgrade net-snmp to 5.9.5 for CVE-2025-68615 [AUTOPATCHER-CORE] Upgrade net-snmp to 5.9.5 for CVE-2025-68615 [Critical] Dec 23, 2025
Update version from 5.9.4 to 5.9.5 in configure script.
@Kanishk-Bansal
Copy link
Contributor

Buddy Build

@Kanishk-Bansal Kanishk-Bansal self-assigned this Dec 25, 2025
@Kanishk-Bansal Kanishk-Bansal added the CVEFixReadyForMaintainerReview When a CVE fix has been reviewed by release manager and is ready for stable maintainer review label Dec 26, 2025
Copy link
Collaborator

@jslobodzian jslobodzian left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

same frr build failure as in 3.0

@Kanishk-Bansal
Copy link
Contributor

closing in favour of #15409

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Automatic PR AutoUpgrade Core CVEFixReadyForMaintainerReview When a CVE fix has been reviewed by release manager and is ready for stable maintainer review fasttrack/2.0 PRs Destined for Azure Linux 2.0 Packaging security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants