[AutoPR- Security] Patch bison for CVE-2026-56390, CVE-2026-56389 [MEDIUM] - #18260
[AutoPR- Security] Patch bison for CVE-2026-56390, CVE-2026-56389 [MEDIUM]#18260azurelinux-security wants to merge 2 commits into
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
Buddy Build has been triggered and it has passed. |
|
Patch analysis
CVE-2026-56390:
Upstream changes not required for this backport:
Suggested Fix-ups
bison-3.8.2-*.rpm fails the license-check gate with: duplicated license files: /usr/share/doc/bison/COPYING
|

Auto Patch bison for CVE-2026-56390, CVE-2026-56389.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1171279&view=results
CVE-2026-56390 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1171289&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology