-
Notifications
You must be signed in to change notification settings - Fork 314
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Release notes 11/28 (20231112, 20231119, 20231126) #4012
Conversation
* [CVE-2023-5043](https://github.com/advisories/GHSA-qppj-fm5r-hxr3) | ||
* Azure Linux image has been updated to [Azure Linux - xxxx](vhd-notes/AzureLinux/xxxx.txt). | ||
* AKS Ubuntu 22.04 image has been updated to [AKSUbuntu-xxxx](vhd-notes/aks-ubuntu/AKSUbuntu-2204/xxxx.txt). | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
NPD version updated to fix CVE-xxxx. Note that this change is not tied to node image upgrade, this rollout will happen outside of the regular upgrade schedule.
@shanalily Can you add some of the details which CVE was fixed, the version of NPD and when the rollout started
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
NPD upgrade on mariner nodes fixes CVE-2014-9940 by upgrading to 0.8.10. Mariner nodes are on an older NPD version than other linux nodes. The release started last Friday, 12/1.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good to resolve this? @aritraghosh @shanalily
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we add Shoshana's comment in the bugs section
18f00de
to
4010af3
Compare
Looks good to me. |
CHANGELOG.md
Outdated
* Under some conditions it was possible to upgrade to Azure CNI Overlay from Kubenet while using the Calico network policy. This scenario is now blocked. | ||
|
||
* Behavioral Change | ||
* Increased coredns memory limits. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
From what to what?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Removed as it is a toggle change
This is a placeholder. Please update the pull request when the 2023-11-28 release is out.