[AutoPR- Security] Patch openssh for CVE-2026-73283, CVE-2026-73282, CVE-2026-73281 [MEDIUM] - #18465
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
The AI-generated openssh.spec changes were incorrect and caused the build to fail. The spec was corrected as follows: • Moved the three patch applications from the beginning of %prep to after Patch415. CVE-2026-73281 Backported: yes (AI patch is ok). CVE-2026-73283 Changes made in serverloop.c: Note: The patches have been successfully applied, and local build has been passed. |


Auto Patch openssh for CVE-2026-73283, CVE-2026-73282, CVE-2026-73281.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1183633&view=results
CVE-2026-73282 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1183638&view=results
CVE-2026-73281 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1183639&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology