Skip to content

[AUTO-CHERRYPICK] [AutoPR- Security] Patch qemu for CVE-2026-3195 [HIGH] - branch 3.0-dev#17860

Open
CBL-Mariner-Bot wants to merge 3 commits into
3.0-devfrom
cblmargh/cherry-pick-pr-17830-to-3.0-dev
Open

[AUTO-CHERRYPICK] [AutoPR- Security] Patch qemu for CVE-2026-3195 [HIGH] - branch 3.0-dev#17860
CBL-Mariner-Bot wants to merge 3 commits into
3.0-devfrom
cblmargh/cherry-pick-pr-17830-to-3.0-dev

Conversation

@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator

This is an auto-generated pull request to cherry-pick commit 4f239ee to 3.0-dev. Original PR: #17830
In case of no merge conflicts, the PR is merged without approval because it's an automated cherry-pick of an already approved PR.
In case of merge conflicts, an AI-based conflict resolver will attempt to resolve conflicts and might make mistakes. The reviewer must check AI's work before approving.

@CBL-Mariner-Bot CBL-Mariner-Bot added the Auto Fast-track Cherry-pick Automatic cherry-pick from fast-track branch label Jun 30, 2026
@CBL-Mariner-Bot CBL-Mariner-Bot marked this pull request as ready for review June 30, 2026 01:33
@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator Author

All conflicts resolved.

@CBL-Mariner-Bot CBL-Mariner-Bot requested a review from a team as a code owner June 30, 2026 01:33
@CBL-Mariner-Bot

Copy link
Copy Markdown
Collaborator Author

Auto Cherry-Pick SPEC Validation Summary

qemu SPEC summary

Source (fasttrack) Target (3.0-dev) Resolved
Version 9.1.0 9.1.0 9.1.0
Release 8 8 10
Patches 31 31 32
Conflict Yes

⚠️ Validation issues:

  • Duplicate changelog entry for 9.1.0-2 (appears 2 times)
  • Duplicate changelog entry for 9.1.0-1 (appears 2 times)
  • Changelog out of order: 9.1.0-1 appears before 9.1.0-6

⚠️ Manual review required — validation found issues that may need correction.

The auto cherry-pick produced empty changelog headers for -10 and -9
and replaced the existing -8 entry (CVE-2026-48914, Wed Jun 17) with
the new CVE-2026-3195 entry, losing the original. Reorder so the new
patch lands at -9 and the existing -8 stays intact. Also rebase the
older entries (-6, -5, -4, -3, -2, -1) back to their proper descending
order which had been scrambled by the auto-merge.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@jslobodzian

Copy link
Copy Markdown
Collaborator

[Toolio Iglesias🗺️] Pushed a fixup commit to correct several auto-merge artifacts:

  • Release number: 10 → 9 (only +1 over 3.0-dev's existing 8, since we're adding exactly one new patch on top of CVE-2026-48914).
  • Lost changelog entry restored: The original 3.0-dev -8\ (Wed Jun 17 2026 — Patch for CVE-2026-48914) had been overwritten. It's now preserved.
  • New entry placement: CVE-2026-3195 now lives at -9\ (Sat Jun 27 2026) sitting above the preserved -8.
  • Empty changelog headers removed: The auto-merge had inserted two empty -10\ and -9\ entries with no body.
  • Day-of-week corrected: -7\ header restored to \Wed May 20\ (calendar-correct).
  • Older entries restored: -6, -5, -4, -3, -2, -1\ were missing or out of order; full descending sequence is now reinstated from the 3.0-dev baseline.

Net effect: the diff vs 3.0-dev is now minimal — Release bump, one new \Patch31\ insertion (existing CVE-2026-48914 bumped to \Patch32), and one new -9\ changelog entry. Ready for re-review.

@Kanishk-Bansal Kanishk-Bansal force-pushed the cblmargh/cherry-pick-pr-17830-to-3.0-dev branch from 7d64348 to 61fe3bb Compare June 30, 2026 05:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.0-dev PRs Destined for AzureLinux 3.0 Auto Fast-track Cherry-pick Automatic cherry-pick from fast-track branch Automatic PR Packaging

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants