[AutoPR- Security] Patch hvloader for CVE-2025-2295 [LOW]#15445
Conversation
|
Patch Modified: NO
|
There was a problem hiding this comment.
nit: please correct the indentation of these lines, though the added lines have proper indentation but from line 32 to 37 needs correction in indentation as then have .
kgodara912
left a comment
There was a problem hiding this comment.
As such patch looks fine. Please address minor older changelog entry correction.
| * Tue Jan 06 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.0.1-16 | ||
| - Bump release for consistency with hvloader spec. | ||
|
|
||
| * Wed Nov 20 2025 Jyoti kanase <v-jykanase@microsoft.com> - 1.0.1-15 |
There was a problem hiding this comment.
nit: bogus date in %changelog: Wed Nov 20 2025
kgodara912
left a comment
There was a problem hiding this comment.
Patch matches with upstream reference. Buddy build is successful. LGTM.

Auto Patch hvloader for CVE-2025-2295.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1019746&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology