From ec751ed16315289a7e8a137ea8d42b92e9e5a217 Mon Sep 17 00:00:00 2001 From: Jindrich Novy Date: Thu, 13 Mar 2025 14:38:21 +0100 Subject: [PATCH] podman-5.4.0-3.el10 - update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel (https://github.com/containers/podman/commit/45c2d1f) - fixes "CVE-2025-27144 podman: Go JOSE's Parsing Vulnerable to Denial of Service [rhel-10.1]" - Resolves: RHEL-80610 Signed-off-by: Jindrich Novy --- podman.spec | 10 ++++++++-- sources | 2 +- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/podman.spec b/podman.spec index 3c3dddf..dc82570 100644 --- a/podman.spec +++ b/podman.spec @@ -9,7 +9,7 @@ %global import_path github.com/containers/podman %global branch v5.4-rhel -%global commit0 5e3accd612e57d8e246041b459f9bf5115954bbc +%global commit0 45c2d1f6a5a63e5b0d1a50cb4ffd826efd412673 %global shortcommit0 %(c=%{commit0}; echo ${c:0:7}) %global gomodulesmode GO111MODULE=on @@ -63,7 +63,7 @@ Epoch: 6 Version: 5.4.0 # The `AND` needs to be uppercase in the License for SPDX compatibility License: Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0 -Release: 2%{?dist} +Release: 3%{?dist} %if %{defined golang_arches_future} ExclusiveArch: %{golang_arches_future} %else @@ -390,6 +390,12 @@ ln -s ../virtiofsd %{buildroot}%{_libexecdir}/%{name} %endif %changelog +* Thu Mar 13 2025 Jindrich Novy - 6:5.4.0-3 +- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel + (https://github.com/containers/podman/commit/45c2d1f) +- fixes "CVE-2025-27144 podman: Go JOSE's Parsing Vulnerable to Denial of Service [rhel-10.1]" +- Resolves: RHEL-80610 + * Fri Mar 07 2025 Jindrich Novy - 6:5.4.0-2 - update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel (https://github.com/containers/podman/commit/5e3accd) diff --git a/sources b/sources index 07640d1..eac321e 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (v5.4-rhel-5e3accd.tar.gz) = ef83d9df34d97bd6253c3110d5ef270987163b3789b37605b84fd9bfe0008e9c44cdbe782fc2f38f63b1bf60b8061cb28e0aaba59a39a3021fd09e7d49d68493 +SHA512 (v5.4-rhel-45c2d1f.tar.gz) = 746dc81d611df59a1b18cd3d794936ddcd8c224333c861c0981245a4d5f1be92d1708c000eb0fc1f41c5bb593139f24da86e7d9d5fa1c682fb25448d9f1c605e