gogo protobuf CVE-2021-3121

Bug #1925968 reported by Sergio Durigan Junior
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
telegraf
Fix Released
Unknown
telegraf (Ubuntu)
Fix Released
Medium
Sergio Durigan Junior
Hirsute
Won't Fix
Medium
Sergio Durigan Junior
Impish
Fix Released
Medium
Sergio Durigan Junior

Bug Description

The gogo protobuf module that is being used by the image (version 1.3.1) has a vulnerability:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3121

Since this module is bundled (vendorized) inside the source package, we need to update it.

Related branches

Changed in telegraf (Ubuntu):
importance: Undecided → Medium
Changed in telegraf:
status: Unknown → New
Changed in telegraf:
status: New → Fix Released
Changed in telegraf (Ubuntu Hirsute):
status: New → Triaged
importance: Undecided → Medium
assignee: nobody → Sergio Durigan Junior (sergiodj)
status: Triaged → Fix Released
status: Fix Released → Triaged
Changed in telegraf (Ubuntu Impish):
status: Triaged → Fix Released
Revision history for this message
Sergio Durigan Junior (sergiodj) wrote :

Unfortunately, I don't have enough time to fix this issue on Hirsute. On top of that, Hirsute is almost EOL'd anyway.

Changed in telegraf (Ubuntu Hirsute):
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.