sonic-buildimage/platform
xumia a6437d8ab6
[202305] Support FIPS for armhf (#18283)
* [Security] Fix the krb5 vulnerability issue (#17914)

### Why I did it
Fix the krb5 vulnerable issue
CVE-2021-36222  allows remote attackers to cause a NULL pointer dereference and daemon crash
CVE-2021-37750  NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field
DSA 5286-1  remote code execution

##### Work item tracking
- Microsoft ADO **(number only)**: 26577929

#### How I did it
Upgrade the krb5 version to 1.18.3-6+deb11u14+fips.

* [Build] Fix krb5 package not found issue (#17926)

Why I did it
Fix the build issue caused by the wrong version specified.

See the build error logs:

Try 4: /usr/bin/wget --retry-connrefused failed to get: -O
--2024-01-26 11:38:23--  https://sonicstorage.blob.core.windows.net/public/fips/bullseye/0.10/amd64/libk5crypto3_1.18.3-6+deb11u14+fips_amd64.deb
Resolving sonicstorage.blob.core.windows.net (sonicstorage.blob.core.windows.net)... 20.60.59.131
Connecting to sonicstorage.blob.core.windows.net (sonicstorage.blob.core.windows.net)|20.60.59.131|:443... connected.
HTTP request sent, awaiting response... 404 The specified blob does not exist.
2024-01-26 11:38:23 ERROR 404: The specified blob does not exist..

Try 5: /usr/bin/wget --retry-connrefused failed to get: -O
make[1]: *** [Makefile:12: /sonic/target/debs/bullseye/symcrypt-openssl_0.10_amd64.deb] Error 8
make[1]: Leaving directory '/sonic/src/sonic-fips'
Work item tracking
Microsoft ADO (number only): 26577929
The package not installed but PR passed issue is traced in another issue #17927

How I did it
Add the libkrb5-dev and the depended packages to fix docker-sonic-vs build failure.
The package libzmq3-dev has dependency on the libkrb5-dev.

* [202305] Support FIPS for armhf

* Remove no use mirror

* Fix fips options issue
2024-03-09 11:39:12 +08:00
..
barefoot [202305] Update Linux kernel to 5.10.179 (#16958) 2023-10-23 22:37:30 +08:00
broadcom [202305] [build] Use public storage for public resources. (#18199) 2024-02-28 08:58:56 -08:00
cavium [infra] Support syslog rate limit configuration (#12490) 2022-12-20 10:53:58 +02:00
centec [202305] Update Linux kernel to 5.10.179 (#16958) 2023-10-23 22:37:30 +08:00
centec-arm64 [202305] Update Linux kernel to 5.10.179 (#16958) 2023-10-23 22:37:30 +08:00
checkout Update cisco-8000.ini (#18154) 2024-02-22 23:14:17 +08:00
components [202305] [build] Use public storage for public resources. (#18199) 2024-02-28 08:58:56 -08:00
generic [dockers] Rename 'docker-snmp-sv2' to 'docker-snmp' (#4699) 2020-06-11 16:04:23 -07:00
innovium Add debug shell packages for Marvell Innovium platforms (#11845) 2023-04-13 22:04:36 +03:00
marvell [infra] Support syslog rate limit configuration (#12490) 2022-12-20 10:53:58 +02:00
marvell-arm64 [Marvell-arm64] Support lazy install of sdk drivers (#17135) 2023-11-16 21:24:53 +08:00
marvell-armhf [Nokia-7215-T1] Disable sysrq-trigger from platform init (#18161) 2024-03-01 01:01:08 +08:00
mellanox [202305][Mellanox]Update SDK/FW to 4.6.2202/2012.2202 (#17946) 2024-01-31 13:33:36 +08:00
nephos [202305] [build] Use public storage for public resources. (#18199) 2024-02-28 08:58:56 -08:00
p4 [infra] Support syslog rate limit configuration (#12490) 2022-12-20 10:53:58 +02:00
pddf [pddf]: Adding S3IP supported attribute for FAN in PDDF (#15075) 2023-05-18 14:06:46 -07:00
s3ip-sysfs The CPLD and FPGA driver framework module complies with s3ip sysfs specification (#12891) 2022-12-16 22:05:53 +08:00
template Mount directory warmboot in docker gbsyncd (#11852) 2022-08-26 22:00:45 +08:00
vs [202305] Support FIPS for armhf (#18283) 2024-03-09 11:39:12 +08:00