Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package istioctl for openSUSE:Factory checked in at 2026-08-28 19:56:30 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/istioctl (Old) and /work/SRC/openSUSE:Factory/.istioctl.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "istioctl" Fri Aug 28 19:56:30 2026 rev:54 rq:1374389 version:1.30.4 Changes: -------- --- /work/SRC/openSUSE:Factory/istioctl/istioctl.changes 2026-07-17 18:49:00.560300848 +0200 +++ /work/SRC/openSUSE:Factory/.istioctl.new.1265/istioctl.changes 2026-08-28 19:59:06.656575989 +0200 @@ -1,0 +2,66 @@ +Fri Aug 28 12:17:49 UTC 2026 - Johannes Kastl <[email protected]> + +- update to 1.30.4: + https://istio.io/latest/news/releases/1.30.x/announcing-1.30.4/ + * Security update + https://istio.io/latest/news/security/istio-security-2026-006/ + - Envoy CVEs + - CVE-2026-73513: (CVSS score 7.5): Fixed a heap + use-after-free where an untrusted upstream could send + HTTP/2 response trailers without the END_STREAM flag to an + Envoy instance using oghttp2, corrupting stream state and + terminating the process. + - CVE-2026-73552: (CVSS score 7.5): Fixed an issue where + safe_regex matching treated accepted non-UTF-8 HTTP header + bytes as a non-match; in RBAC policies using negative + matching this could fail open and allow access to a + protected resource. + - CVE-2026-73512: (CVSS score 7.5): Fixed a use-after-free in + the QUIC HTTP datagram handler where late HTTP/3 datagrams + could reference a stream decoder that was already destroyed + or replaced. + - CVE-2026-73547: (CVSS score 7.5): Fixed an abnormal process + termination in the ext_authz filter when processing CONNECT + requests without a :path pseudo-header. + - CVE-2026-73549: (CVSS score 5.3): Fixed an abnormal process + termination for scoped IPv6 client addresses in original + DST clusters with HTTP/3. + - CVE-2026-50572: (CVSS score 5.9): Fixed a use-after-free in + the ext_authz raw HTTP client where completing an + authorization request could destroy the client while its + completion handler was still executing. + - CVE-2026-73546: (CVSS score 7.4): Fixed a stored cross-site + scripting issue in the HTML stats interface + (/stats?format=html) where dynamically named statistics + could introduce attacker-controlled content. + - CVE-2026-48521: (CVSS score 5.9): Fixed an abnormal process + termination where Envoy could dereference null transport + socket options during ALPN-based HTTP/3 connection-pool + selection. + - CVE-2026-73551: (CVSS score 5.3): Fixed URL normalization + of dot and dot-dot path segments containing parameters, + which could cause access-control components and upstream + applications to interpret a request path differently. + - CVE-2026-73511: (CVSS score 5.3): Fixed path matching for + paths containing per-segment parameters, where Envoy and + backends could select different resources for the same + request and bypass path-based selection or authentication. + - CVE-2026-73548: (CVSS score 7.5): Fixed cross-user response + poisoning involving generic, non-WebSocket HTTP upgrades, + where request payload sent before an upgrade was accepted + could contaminate a shared upstream connection. + - CVE-2026-73550: (CVSS score 7.5): Fixed an HTTP/2 + memory-exhaustion issue where discarded duplicate Host + headers were not counted toward request-header size and + count limits. + - CVE-2026-73553: (CVSS score 7.5): Fixed an authorization + bypass when ignore_path_parameters_in_path_matching was + enabled, where a path such as /admin;x could bypass an RBAC + policy for /admin while still reaching the protected route. + - Istio CVEs + - GHSA-qm8v-g4f9-qhjx (CVSS score 6.8, Moderate): + BackendTLSPolicy fails open to plaintext on sidecar proxies + when its CA reference is unresolved. Reported by @thc1006. + * No istioctl-related changes + +------------------------------------------------------------------- Old: ---- istioctl-1.30.3.obscpio New: ---- istioctl-1.30.4.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ istioctl.spec ++++++ --- /var/tmp/diff_new_pack.Xc1v3c/_old 2026-08-28 19:59:08.914654935 +0200 +++ /var/tmp/diff_new_pack.Xc1v3c/_new 2026-08-28 19:59:08.919655110 +0200 @@ -17,7 +17,7 @@ Name: istioctl -Version: 1.30.3 +Version: 1.30.4 Release: 0 Summary: CLI for the istio servic mesh in Kubernetes License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.Xc1v3c/_old 2026-08-28 19:59:08.993657697 +0200 +++ /var/tmp/diff_new_pack.Xc1v3c/_new 2026-08-28 19:59:08.998657872 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/istio/istio.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/1.30.3</param> + <param name="revision">refs/tags/1.30.4</param> <param name="versionformat">@PARENT_TAG@</param> <param name="changesgenerate">disable</param> <param name="filename">istioctl</param> ++++++ istioctl-1.30.3.obscpio -> istioctl-1.30.4.obscpio ++++++ ++++ 15494 lines of diff (skipped) ++++++ istioctl.obsinfo ++++++ --- /var/tmp/diff_new_pack.Xc1v3c/_old 2026-08-28 19:59:13.737823561 +0200 +++ /var/tmp/diff_new_pack.Xc1v3c/_new 2026-08-28 19:59:13.747823911 +0200 @@ -1,5 +1,5 @@ name: istioctl -version: 1.30.3 -mtime: 1783961794 -commit: 56df41f63e513f834c9a3af33d8aed82d1d961f2 +version: 1.30.4 +mtime: 1787783972 +commit: 4220640be99e4cad69652d9eb2010bc5257f6a8e ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/istioctl/vendor.tar.gz /work/SRC/openSUSE:Factory/.istioctl.new.1265/vendor.tar.gz differ: char 13, line 1
