Fix cve issue #1

Manually merged
dimstar_suse merged 12 commits from hillwood/v2ray-core:leap-16.0 into leap-16.0 2025-11-28 14:29:00 +01:00
Contributor

Fix cve issue

Fix cve issue
hillwood added 12 commits 2025-11-25 15:41:47 +01:00
* Add packetEncoding for Hysteria
  * Add ECH Client Support
  * Add support for parsing some shadowsocks links
  * Add Mekya Transport
  * Fix bugs

OBS-URL: https://build.opensuse.org/package/show/server:proxy/v2ray-core?expand=0&rev=54
- Update version to 5.22.0
  * Add packetEncoding for Hysteria
  * Add ECH Client Support
  * Add support for parsing some shadowsocks links
  * Add Mekya Transport
  * Fix bugs (forwarded request 1225824 from hillwood)

OBS-URL: https://build.opensuse.org/request/show/1225825
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/v2ray-core?expand=0&rev=28
* Enable restricted mode load for http protocol client
  * Correctly implement QUIC sniffer when handling multiple initial packets
  * Fix unreleased cache buffer in QUIC sniffing
  * A temporary testing fix for the buffer corruption issue
  * QUIC Sniffer Restructure

OBS-URL: https://build.opensuse.org/package/show/server:proxy/v2ray-core?expand=0&rev=56
OBS-URL: https://build.opensuse.org/request/show/1267381
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/v2ray-core?expand=0&rev=29
* Add Dns Proxy Response TTL Control
  * Fix call newError Base with a nil value error
  * Update vendor (boo#1235164)

OBS-URL: https://build.opensuse.org/package/show/server:proxy/v2ray-core?expand=0&rev=58
OBS-URL: https://build.opensuse.org/request/show/1274232
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/v2ray-core?expand=0&rev=30
* bump github.com/quic-go/quic-go from 0.51.0 to 0.52.0(boo#1243946 and CVE-2025-297850)
  * Update other vendor source

OBS-URL: https://build.opensuse.org/package/show/server:proxy/v2ray-core?expand=0&rev=60
- Update version to 5.33.0
  * bump github.com/quic-go/quic-go from 0.51.0 to 0.52.0(boo#1243946 and CVE-2025-297850)
  * Update other vendor source (forwarded request 1281928 from hillwood)

OBS-URL: https://build.opensuse.org/request/show/1281929
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/v2ray-core?expand=0&rev=31
* TLSMirror Connection Enrollment System
  * Add TLSMirror Sequence Watermarking
  * LSMirror developer preview protocol is now a part of mainline V2Ray
  * proxy dns with NOTIMP error
  * Add TLSMirror looks like TLS censorship resistant transport protocol
    as a developer preview transport
  * proxy dns with NOTIMP error
  * fix false success from SOCKS server when Dispatch() fails
  * HTTP inbound: Directly forward plain HTTP 1xx response header
  * add a option to override domain used to query https record
  * Fix bugs
  * Update vendor

OBS-URL: https://build.opensuse.org/package/show/server:proxy/v2ray-core?expand=0&rev=62
- Update version to 5.38.0
  * TLSMirror Connection Enrollment System
  * Add TLSMirror Sequence Watermarking
  * LSMirror developer preview protocol is now a part of mainline V2Ray
  * proxy dns with NOTIMP error
  * Add TLSMirror looks like TLS censorship resistant transport protocol
    as a developer preview transport
  * proxy dns with NOTIMP error
  * fix false success from SOCKS server when Dispatch() fails
  * HTTP inbound: Directly forward plain HTTP 1xx response header
  * add a option to override domain used to query https record
  * Fix bugs
  * Update vendor (forwarded request 1304079 from hillwood)

OBS-URL: https://build.opensuse.org/request/show/1304080
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/v2ray-core?expand=0&rev=32
* Add fix-CVE-2025-47911.patch
  * Update golang.org/x/net to 0.45.0 in vendor

OBS-URL: https://build.opensuse.org/package/show/server:proxy/v2ray-core?expand=0&rev=64
- Fix CVE-2025-47911 and boo#1251404
  * Add fix-CVE-2025-47911.patch
  * Update golang.org/x/net to 0.45.0 in vendor (forwarded request 1309804 from hillwood)

OBS-URL: https://build.opensuse.org/request/show/1310006
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/v2ray-core?expand=0&rev=33
autogits_workflow_pr_bot requested review from legaldb 2025-11-25 15:42:11 +01:00
autogits_workflow_pr_bot requested review from maintenance-release-review 2025-11-25 15:42:11 +01:00
autogits_workflow_pr_bot requested review from opensuse-review 2025-11-25 15:42:11 +01:00
First-time contributor

Review by maintenance-release-review represents a group of reviewers: abergmann, amattiazzo, bfilho, cmatos, crazybyte, emanuelecappello, gsonnu, maintenance-robot, mauriziogalli, mbozicevic, mimi_vx, mschnitzer, msmeissn, pluskalm, rfrohl, slemke .

Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment: @maintenance-release-review: approve.
To request changes on behalf of the group, create the following comment: @maintenance-release-review: decline followed with lines justifying the decision.
Future edits of the comments are ignored, a new comment is required to change the review state.

Review by maintenance-release-review represents a group of reviewers: abergmann, amattiazzo, bfilho, cmatos, crazybyte, emanuelecappello, gsonnu, maintenance-robot, mauriziogalli, mbozicevic, mimi_vx, mschnitzer, msmeissn, pluskalm, rfrohl, slemke . Do **not** use standard review interface to review on behalf of the group. To accept the review on behalf of the group, create the following comment: `@maintenance-release-review: approve`. To request changes on behalf of the group, create the following comment: `@maintenance-release-review: decline` followed with lines justifying the decision. Future edits of the comments are ignored, a new comment is required to change the review state.

Review by opensuse-review represents a group of reviewers: alarrosa, anag, atartamo, bigironman, darix, dimstar, dmach, eroca, jdsn, jengelh, mcalabkova, mstrigl, nkrapp, oertel, RBrownSUSE, simotek, smithfarm .

Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment: @opensuse-review: approve.
To request changes on behalf of the group, create the following comment: @opensuse-review: decline followed with lines justifying the decision.
Future edits of the comments are ignored, a new comment is required to change the review state.

Review by opensuse-review represents a group of reviewers: alarrosa, anag, atartamo, bigironman, darix, dimstar, dmach, eroca, jdsn, jengelh, mcalabkova, mstrigl, nkrapp, oertel, RBrownSUSE, simotek, smithfarm . Do **not** use standard review interface to review on behalf of the group. To accept the review on behalf of the group, create the following comment: `@opensuse-review: approve`. To request changes on behalf of the group, create the following comment: `@opensuse-review: decline` followed with lines justifying the decision. Future edits of the comments are ignored, a new comment is required to change the review state.
Member

Legal reviewed as acceptable_by_lawyer:

Accepted because previously reviewed under the same license (475886)
Legal reviewed as [acceptable_by_lawyer](https://legaldb.suse.de/reviews/details/491204): ``` Accepted because previously reviewed under the same license (475886) ```
1.2 KiB
legaldb approved these changes 2025-11-25 15:53:36 +01:00
First-time contributor

@maintenance-release-review: approve
merge ok

@maintenance-release-review: approve merge ok
maintenance-release-review approved these changes 2025-11-27 13:37:46 +01:00
First-time contributor

rfrohl approved a review on behalf of maintenance-release-review

rfrohl approved a review on behalf of maintenance-release-review
First-time contributor

@opensuse-review : approve

LGTM

@opensuse-review : approve LGTM
First-time contributor

merge ok

merge ok
opensuse-review approved these changes 2025-11-27 13:49:22 +01:00
opensuse-review left a comment
Member

oertel approved a review on behalf of opensuse-review

oertel approved a review on behalf of opensuse-review
dimstar_suse manually merged commit 8335900c7d into leap-16.0 2025-11-28 14:29:00 +01:00
Sign in to join this conversation.