[release-2.14] Fix CVE-2026-42154: validate snappy decoded length in remote read - #362
Conversation
…oint Fix CVE-2026-42154 Cherry-pick of 497f898 from release-2.17 Jira: ACM-35459 - https://redhat.atlassian.net/browse/ACM-35459 Signed-off-by: Julien Pivotto <291750+roidelapluie@users.noreply.github.com> Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Kate Barreiros <kbarreir@redhat.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: katekeiroz-dev The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/retest |
|
@katekeiroz-dev: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary
497f8989bfromrelease-2.17/api/v1/read)CVE
Jira
ACM-35459
Test plan
TestDecodeReadRequestTooLarge