Skip to content

ITEP-89363 : Patch for vulnerabilty reported in fluent-bit#886

Merged
cheeyanglee merged 1 commit intoopen-edge-platform:26.06from
bunnichx:cve-fluent-bit
Apr 20, 2026
Merged

ITEP-89363 : Patch for vulnerabilty reported in fluent-bit#886
cheeyanglee merged 1 commit intoopen-edge-platform:26.06from
bunnichx:cve-fluent-bit

Conversation

@bunnichx
Copy link
Copy Markdown
Contributor

  • Patch for CVE-2026-27135.

Merge Checklist

All boxes should be checked before merging the PR

  • The changes in the PR have been built and tested
  • [] cgmanifest file has been updated if required
  • Ready to merge

Description

Patch for CVE-2026-27135 based on commit in nghttp2

Any Newly Introduced Dependencies

How Has This Been Tested?

Developer build with id #1800 is success.
Loaded generated iso and installed fluent-bit without issues.
checked rpm build load and verified CVE-2026-27135.patch applied successfully.
RPM build log:

time="2026-04-17T17:35:49+05:30" level=debug msg="+ /usr/lib/rpm/rpmuncompress /usr/src/azl/SOURCES/CVE-2026-27135.patch"
time="2026-04-17T17:35:49+05:30" level=debug msg="+ /usr/bin/patch -p1 -s --fuzz=0 --no-backup-if-mismatch -f"
time="2026-04-17T17:35:49+05:30" level=debug msg="+ RPM_EC=0"
time="2026-04-17T17:35:49+05:30" level=debug msg="++ jobs -p"
time="2026-04-17T17:35:49+05:30" level=debug msg="+ exit 0"
time="2026-04-17T17:35:49+05:30" level=debug msg="Executing(%build): /bin/sh -e /var/tmp/rpm-tmp.Ir5MIA"

 - Patch for CVE-2026-27135.

Signed-off-by: Unniche, BasavarajX <basavarajx.unniche@intel.com>
@bunnichx bunnichx requested a review from a team as a code owner April 18, 2026 17:21
@cheeyanglee cheeyanglee merged commit 647538e into open-edge-platform:26.06 Apr 20, 2026
9 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants