[AutoPR- Security] Patch edk2 for CVE-2026-75803, CVE-2026-63076, CVE-2026-63074, CVE-2026-63072 [HIGH] - #18638
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
CVE-2026-54874 - Patch has been removed as it is being disputed.
Re-triggered Buddy Build and it has passed. |
|
Kindly update PR title to remove CVE-2026-54874. |
|
[Toolio Iglesias🗺️] kanishk Bansal — flagging a title/content discrepancy on this PR for your awareness: The PR title and Summary list 5 CVEs (CVE-2026-75803, CVE-2026-63076, CVE-2026-63074, CVE-2026-63072, CVE-2026-54874), but the actual change only adds 4 patch files and the
The spec is internally consistent for the 4 CVEs it does patch (Release 18→19, signed variant bumped in lockstep, FT build 1192826 green). But please confirm whether CVE-2026-54874 was intentionally dropped (e.g., no backport available yet) or accidentally omitted — and either update the title/Summary to match, or add the missing patch before this merges. |
jslobodzian - The patch for CVE-2026-54874 has been removed as it has been disputed after discussing with the MSRC team. Refer PR comment - #18638 (comment) Kanishk Bansal (@Kanishk-Bansal) - Could you please update the PR, as it still has references of CVE-2026-54874 in sections such as |
|
Done |
Auto Patch edk2 for CVE-2026-75803, CVE-2026-63076, CVE-2026-63074, CVE-2026-63072.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1191369&view=results
CVE-2026-75803 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1191379&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology