Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package istioctl for openSUSE:Factory 
checked in at 2026-08-28 19:56:30
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/istioctl (Old)
 and      /work/SRC/openSUSE:Factory/.istioctl.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "istioctl"

Fri Aug 28 19:56:30 2026 rev:54 rq:1374389 version:1.30.4

Changes:
--------
--- /work/SRC/openSUSE:Factory/istioctl/istioctl.changes        2026-07-17 
18:49:00.560300848 +0200
+++ /work/SRC/openSUSE:Factory/.istioctl.new.1265/istioctl.changes      
2026-08-28 19:59:06.656575989 +0200
@@ -1,0 +2,66 @@
+Fri Aug 28 12:17:49 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- update to 1.30.4:
+  https://istio.io/latest/news/releases/1.30.x/announcing-1.30.4/
+  * Security update
+    https://istio.io/latest/news/security/istio-security-2026-006/
+    - Envoy CVEs
+      - CVE-2026-73513: (CVSS score 7.5): Fixed a heap
+        use-after-free where an untrusted upstream could send
+        HTTP/2 response trailers without the END_STREAM flag to an
+        Envoy instance using oghttp2, corrupting stream state and
+        terminating the process.
+      - CVE-2026-73552: (CVSS score 7.5): Fixed an issue where
+        safe_regex matching treated accepted non-UTF-8 HTTP header
+        bytes as a non-match; in RBAC policies using negative
+        matching this could fail open and allow access to a
+        protected resource.
+      - CVE-2026-73512: (CVSS score 7.5): Fixed a use-after-free in
+        the QUIC HTTP datagram handler where late HTTP/3 datagrams
+        could reference a stream decoder that was already destroyed
+        or replaced.
+      - CVE-2026-73547: (CVSS score 7.5): Fixed an abnormal process
+        termination in the ext_authz filter when processing CONNECT
+        requests without a :path pseudo-header.
+      - CVE-2026-73549: (CVSS score 5.3): Fixed an abnormal process
+        termination for scoped IPv6 client addresses in original
+        DST clusters with HTTP/3.
+      - CVE-2026-50572: (CVSS score 5.9): Fixed a use-after-free in
+        the ext_authz raw HTTP client where completing an
+        authorization request could destroy the client while its
+        completion handler was still executing.
+      - CVE-2026-73546: (CVSS score 7.4): Fixed a stored cross-site
+        scripting issue in the HTML stats interface
+        (/stats?format=html) where dynamically named statistics
+        could introduce attacker-controlled content.
+      - CVE-2026-48521: (CVSS score 5.9): Fixed an abnormal process
+        termination where Envoy could dereference null transport
+        socket options during ALPN-based HTTP/3 connection-pool
+        selection.
+      - CVE-2026-73551: (CVSS score 5.3): Fixed URL normalization
+        of dot and dot-dot path segments containing parameters,
+        which could cause access-control components and upstream
+        applications to interpret a request path differently.
+      - CVE-2026-73511: (CVSS score 5.3): Fixed path matching for
+        paths containing per-segment parameters, where Envoy and
+        backends could select different resources for the same
+        request and bypass path-based selection or authentication.
+      - CVE-2026-73548: (CVSS score 7.5): Fixed cross-user response
+        poisoning involving generic, non-WebSocket HTTP upgrades,
+        where request payload sent before an upgrade was accepted
+        could contaminate a shared upstream connection.
+      - CVE-2026-73550: (CVSS score 7.5): Fixed an HTTP/2
+        memory-exhaustion issue where discarded duplicate Host
+        headers were not counted toward request-header size and
+        count limits.
+      - CVE-2026-73553: (CVSS score 7.5): Fixed an authorization
+        bypass when ignore_path_parameters_in_path_matching was
+        enabled, where a path such as /admin;x could bypass an RBAC
+        policy for /admin while still reaching the protected route.
+    - Istio CVEs
+      - GHSA-qm8v-g4f9-qhjx (CVSS score 6.8, Moderate):
+        BackendTLSPolicy fails open to plaintext on sidecar proxies
+        when its CA reference is unresolved. Reported by @thc1006.
+  * No istioctl-related changes
+
+-------------------------------------------------------------------

Old:
----
  istioctl-1.30.3.obscpio

New:
----
  istioctl-1.30.4.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ istioctl.spec ++++++
--- /var/tmp/diff_new_pack.Xc1v3c/_old  2026-08-28 19:59:08.914654935 +0200
+++ /var/tmp/diff_new_pack.Xc1v3c/_new  2026-08-28 19:59:08.919655110 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           istioctl
-Version:        1.30.3
+Version:        1.30.4
 Release:        0
 Summary:        CLI for the istio servic mesh in Kubernetes
 License:        Apache-2.0

++++++ _service ++++++
--- /var/tmp/diff_new_pack.Xc1v3c/_old  2026-08-28 19:59:08.993657697 +0200
+++ /var/tmp/diff_new_pack.Xc1v3c/_new  2026-08-28 19:59:08.998657872 +0200
@@ -3,7 +3,7 @@
     <param name="url">https://github.com/istio/istio.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">refs/tags/1.30.3</param>
+    <param name="revision">refs/tags/1.30.4</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="changesgenerate">disable</param>
     <param name="filename">istioctl</param>

++++++ istioctl-1.30.3.obscpio -> istioctl-1.30.4.obscpio ++++++
++++ 15494 lines of diff (skipped)

++++++ istioctl.obsinfo ++++++
--- /var/tmp/diff_new_pack.Xc1v3c/_old  2026-08-28 19:59:13.737823561 +0200
+++ /var/tmp/diff_new_pack.Xc1v3c/_new  2026-08-28 19:59:13.747823911 +0200
@@ -1,5 +1,5 @@
 name: istioctl
-version: 1.30.3
-mtime: 1783961794
-commit: 56df41f63e513f834c9a3af33d8aed82d1d961f2
+version: 1.30.4
+mtime: 1787783972
+commit: 4220640be99e4cad69652d9eb2010bc5257f6a8e
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/istioctl/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.istioctl.new.1265/vendor.tar.gz differ: char 13, 
line 1

Reply via email to