8000 OpenCE 1.11.x CVE list · Issue #1324 · open-ce/open-ce · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

OpenCE 1.11.x CVE list #1324

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
mwatk opened this issue Mar 3, 2025 · 6 comments
Open

OpenCE 1.11.x CVE list #1324

mwatk opened this issue Mar 3, 2025 · 6 comments
Labels
enhancement New feature or request

Comments

@mwatk
Copy link
mwatk commented Mar 3, 2025

Summary of candidates to be assessed for the next opence release 1.11.x:

@mwatk mwatk added the enhancement New feature or request label Mar 3, 2025
@mwatk
Copy link
Author
mwatk commented Mar 10, 2025

@cdeepali could you pls assess the 3 items listed. In term of priority:
LightGBM is a high sev findings that we need to fix as soon as possible.
Scikit-learn a due date of April 30.
Keras has due date on Cloud of May 7.

@cdeepali
Copy link
Contributor
cdeepali commented Mar 17, 2025
Package Version in 1.11.5 CVE Version Fixed Upgade/Backport
LightGBM 4.2.0 CVE-2024-43598, https://github.ibm.com/ax/planning/issues/15468 4.6.0 Backport
scikit-learn 1.3.0 CVE-2024-5206, https://github.ibm.com/ax/planning/issues/14648 1.5.0 Backport
keras 2.14.0 CVE-2024-55459, https://github.ibm.com/ax/planning/issues/15333 open Fix not available
pytorch-lightning 2.3.3 CVE-2024-8019, https://github.ibm.com/ax/planning/issues/15601 2.4.0 Skipping as it is Windows Specific
onnx 1.16.0 CVE-2024-7776, https://github.ibm.com/ax/planning/issues/15602 1.17.0 Backport
torch 2.1.2 CVE-2024-7804, https://github.ibm.com/ax/planning/issues/15604 open CVE Withdrawn
transformers 4.37.2 CVE-2024-12720 https://github.ibm.com/ax/planning/issues/15644 4.48.0 Backport as it is pinned in WNLP
langchain-core 0.2.39 CVE-2024-10940 https://github.ibm.com/ax/planning/issues/15628 Fixed in v0.3.15 but latest is 0.3.51 Skipping this because updating to latest requires update in numpy too

@cdeepali cdeepali modified the milestones: OpenCE 1.11.6, OpenCE v1.11.6 Mar 18, 2025
@cdeepali
Copy link
Contributor
cdeepali commented Apr 9, 2025

@rolweber pls suggest if we can update onnx to v1.17.0 in OpenCE v1.11.6 for CVE - GHSA-h36j-8vv3-cj52.

@cdeepali
Copy link
Contributor

While updating langchain-core to v0.3.51 we need to update langchain-community to v0.3.21 and while doing so we have observed that this would require updating numpy to v1.16.2 due to the following error:
langchain-community 0.3.21 has requirement numpy<3,>=1.26.2, but you have numpy 1.26.0.
But numpy version 1.26 is latest on PPC from anaconda, so to support langchain-community v0.3.21 we would need to build numpy v1.26.2 in OpenCE for PPC.
numpy is a widely used dependency so may affect other package families too.

Thus it is concluded to not to update langchain-core in 1.11.6. https://ibm-systems-power.slack.com/archives/C571VTK0T/p1744698311553279?thread_ts=1744120875.281359&cid=C571VTK0T

@mwatk
Copy link
Author
mwatk commented Apr 29, 2025

@cdeepali guess Roland brought this up already, there is another critical one that we should consider if possible https://github.ibm.com/ax/planning/issues/15708

@cdeepali
Copy link
Contributor
cdeepali commented May 6, 2025

Regarding onnx CVE - the fix for GHSA-h36j-8vv3-cj52 is in onnx/onnx@1b70f9b which was included in 1.11.5 as part of fix of another CVE - GHSA-6rq9-53c3-f7vj

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants
0