Skip to content

Conversation

@larryluogit
Copy link

This fix ensures that the iov_base pointers point to the right address.

PiperOrigin-RevId: 673923651

@karthikravis

This fix ensures that the iov_base pointers point to the right address.

PiperOrigin-RevId: 673923651
@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@larryluogit larryluogit changed the title Address CVE-2024-11407 [grpc] Address CVE-2024-11407 Jun 7, 2025
@larryluogit
Copy link
Author

@thevar1able
This PR cherry pick the fix for CVE-2024-11407

@larryluogit
Copy link
Author

@thevar1able @Algunenano
This is a case where a submodule points to a ClickHouse fork.
I'm currently updating the ClickHouse fork to address some CVEs. My process is:

  1. Submit a PR to the ClickHouse fork first
  2. Once that PR is merged, submit another PR to the main ClickHouse branch to update the submodule reference

I'm concerned this might not be the correct approach. Could you please confirm the proper steps for addressing CVEs in ClickHouse submodule forks? TIA

@rschu1ze
Copy link
Member

rschu1ze commented Jun 9, 2025

No worries, this is exactly the right approach.

But before pushing anything, please check the merged and open PRs to avoid duplicate work ... there have been various CVE fixes from our side already:

@thevar1able thevar1able merged commit 53d4f44 into ClickHouse:ClickHouse/v1.59.5 Jun 10, 2025
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants