Skip to content

[release-5.0] OCPBUGS-108014,OCPBUGS-107890,OCPBUGS-107915: UPSTREAM: <carry>: bump otel to v1.44.0 to fix CVE-2026-41178 - #2762

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift:release-5.0from
ehearne-redhat:fix-CVE-2026-41178
Sep 11, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
openshift:release-5.0from
ehearne-redhat:fix-CVE-2026-41178

Conversation

@ehearne-redhat

Copy link
Copy Markdown

This change bumps otel to v1.44.0 across the kubernetes repo. It also updates transient dependencies where necessary.

See https://pkg.go.dev/vuln/GO-2026-5158 for reference.

Keeping this change in release-5.0 to respect 1.37 kube rebase to land in master and release-5.1.

See #2738 for reference.

Also see kubernetes#139380 for reference.
Since release-5.0 is pinned to kube 1.36, this change is necessary as only 1.37+ kubernetes will get this patch for free.

@openshift-merge-bot

Copy link
Copy Markdown

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@openshift-ci-robot openshift-ci-robot added backports/unvalidated-commits Indicates that not all commits come to merged upstream PRs. jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. labels Aug 27, 2026
@coderabbitai

coderabbitai Bot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 24a0e967-91d8-41c8-b0c8-3b75812c4d9d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@openshift-ci-robot openshift-ci-robot added the jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. label Aug 27, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: This pull request references Jira Issue OCPBUGS-108014, which is invalid:

  • expected Jira Issue OCPBUGS-108014 to depend on a bug targeting a version in 5.1.0 and in one of the following states: MODIFIED, ON_QA, VERIFIED, but no dependents were found

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

This change bumps otel to v1.44.0 across the kubernetes repo. It also updates transient dependencies where necessary.

See https://pkg.go.dev/vuln/GO-2026-5158 for reference.

Keeping this change in release-5.0 to respect 1.37 kube rebase to land in master and release-5.1.

See #2738 for reference.

Also see kubernetes#139380 for reference.
Since release-5.0 is pinned to kube 1.36, this change is necessary as only 1.37+ kubernetes will get this patch for free.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: the contents of this pull request could not be automatically validated.

The following commits could not be validated and must be approved by a top-level approver:

Comment /validate-backports to re-evaluate validity of the upstream PRs, for example when they are merged upstream.

@openshift-ci
openshift-ci Bot requested review from jacobsee and p0lyn0mial August 27, 2026 13:00
@openshift-ci openshift-ci Bot added the vendor-update Touching vendor dir or related files label Aug 27, 2026
@ehearne-redhat

Copy link
Copy Markdown
Author

/jira refresh

@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: This pull request references Jira Issue OCPBUGS-108014, which is invalid:

  • expected Jira Issue OCPBUGS-108014 to depend on a bug targeting a version in 5.1.0 and in one of the following states: MODIFIED, ON_QA, VERIFIED, but no dependents were found

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

Details

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@ehearne-redhat

Copy link
Copy Markdown
Author

/jira refresh

@openshift-ci-robot openshift-ci-robot added jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. and removed jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. labels Aug 27, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: This pull request references Jira Issue OCPBUGS-108014, which is valid. The bug has been moved to the POST state.

7 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (5.0.0) matches configured target version for branch (5.0.0)
  • bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, POST)
  • release note type set to "Release Note Not Required"
  • dependent bug Jira Issue OCPBUGS-114602 is in the state MODIFIED, which is one of the valid states (MODIFIED, ON_QA, VERIFIED)
  • dependent Jira Issue OCPBUGS-114602 targets the "5.1.0" version, which is one of the valid target versions: 5.1.0
  • bug has dependents
Details

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: the contents of this pull request could not be automatically validated.

The following commits could not be validated and must be approved by a top-level approver:

Comment /validate-backports to re-evaluate validity of the upstream PRs, for example when they are merged upstream.

@ehearne-redhat

Copy link
Copy Markdown
Author

/test verify

@jubittajohn

Copy link
Copy Markdown

Since release-5.0 is pinned to kube 1.36, this change is necessary as only 1.37+ kubernetes will get this patch for free.

That said, upstream Kubernetes publishes monthly patch releases for each supported minor version (typically four minors maintained at any given time). Given the CVE, I would have expected the fix to land in 1.36.3 or 1.36.4 — both of which shipped without it. The CVSS score is also only 5.3 (medium). I'd like to understand why upstream chose not to backport this before we carry it ourselves. I'll look into the upstream backport policy for this CVE and review the PR accordingly.

Separately, the verify job is failing because staging/src/k8s.io/cri-streaming/go.mod and go.sum are out of date. Could you regenerate them by running hack/update-vendor.sh from within the build container:

  podman run -it --rm \
    -v $(pwd):/go/k8s.io/kubernetes:Z \
    --workdir=/go/k8s.io/kubernetes \
    registry.ci.openshift.org/openshift/release:rhel-9-release-golang-1.26-openshift-5.0 \
    bash -c 'OS_RUN_WITHOUT_DOCKER=yes FORCE_HOST_GO=1 hack/update-vendor.sh'

@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: the contents of this pull request could not be automatically validated.

The following commits could not be validated and must be approved by a top-level approver:

Comment /validate-backports to re-evaluate validity of the upstream PRs, for example when they are merged upstream.

@ehearne-redhat

Copy link
Copy Markdown
Author

@jubittajohn I'm seeing this strange error here in the verify test - do we ignore it?

Your vendored results are different:
diff -Naupr -x 'AUTHORS*' -x 'CONTRIBUTORS*' vendor/go.opentelemetry.io/otel/AGENTS.md /tmp/volume/verify-vendor.sh.uDcwGA/kubernetes/vendor/go.opentelemetry.io/otel/AGENTS.md
--- vendor/go.opentelemetry.io/otel/AGENTS.md	1970-01-01 00:00:00.000000000 +0000
+++ /tmp/volume/verify-vendor.sh.uDcwGA/kubernetes/vendor/go.opentelemetry.io/otel/AGENTS.md	2026-08-31 08:41:09.437410524 +0000

@ehearne-redhat

Copy link
Copy Markdown
Author

/test verify

@jubittajohn

jubittajohn commented Sep 1, 2026

Copy link
Copy Markdown

I'm seeing this strange error here in the verify test - do we ignore it?

kubernetes#137759 — This upstream PR, which was included in 1.36, appears to be the culprit. The AGENTS.md entry in .gitignore should have been scoped more narrowly. As it stands, it also causes vendor/go.opentelemetry.io/otel/AGENTS.md to be ignored, preventing that file from being committed.

This results in a mismatch between the vendored content committed in the PR and the output generated when CI runs go mod vendor, which is causing the verify failure.

kubernetes#138005 - this PR upstream, included in 1.37 is removes AGENTS.md from .gitignore.

I think the two options are:

  1. Force-add the file (git add -f vendor/go.opentelemetry.io/otel/AGENTS.md)
  2. Cherry-pick Add AGENTS.md kubernetes/kubernetes#138005 into 1.36

I also need to look into the upstream backport policy for this CVE. Once we understand that, we can decide which approach to take.(I will also consult with Jacob/Fabio)

@ehearne-redhat

Copy link
Copy Markdown
Author

No worries @jubittajohn - I will wait for further guidance. Thanks for looking into this. :)

@jacobsee

jacobsee commented Sep 5, 2026

Copy link
Copy Markdown
Member

Hi @ehearne-redhat - I think it is appropriate to git add -f this vendored file for now. It shouldn't be a problem in the future and that will address the verify job's complaints 🙂

This change bumps otel to v1.44.0 across the kubernetes repo.
It also updates transient dependencies where necessary.

See https://pkg.go.dev/vuln/GO-2026-5158 for reference.

Keeping this change in release-5.0 to respect 1.37 kube rebase to
land in master and release-5.1.

See openshift#2738 for reference.

Also see kubernetes#139380 for
reference.
Since release-5.0 is pinned to kube 1.36, this change is necessary
as only 1.37+ kubernetes will get this patch for free.
@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: the contents of this pull request could not be automatically validated.

The following commits could not be validated and must be approved by a top-level approver:

Comment /validate-backports to re-evaluate validity of the upstream PRs, for example when they are merged upstream.

@ehearne-redhat

Copy link
Copy Markdown
Author

/test perfscale-control-plane-6nodes

2 similar comments
@ehearne-redhat

Copy link
Copy Markdown
Author

/test perfscale-control-plane-6nodes

@ehearne-redhat

Copy link
Copy Markdown
Author

/test perfscale-control-plane-6nodes

@jubittajohn

Copy link
Copy Markdown

/lgtm
/approve
/label backport-risk-assessed
/remove-label backports/unvalidated-commits

@openshift-ci openshift-ci Bot added backport-risk-assessed Indicates a PR to a release branch has been evaluated and considered safe to accept. and removed backports/unvalidated-commits Indicates that not all commits come to merged upstream PRs. labels Sep 8, 2026
@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Sep 8, 2026
@openshift-merge-bot

Copy link
Copy Markdown

Scheduling required tests:
/test configmap-scale
/test e2e-aws-ovn-cgroupsv2
/test e2e-aws-ovn-crun
/test e2e-aws-ovn-fips
/test e2e-aws-ovn-serial-1of2
/test e2e-aws-ovn-serial-2of2
/test e2e-gcp
/test e2e-metal-ipi-ovn-ipv6
/test k8s-e2e-conformance-aws
/test k8s-e2e-gcp-ovn
/test k8s-e2e-gcp-serial

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aws-ovn-hypershift

@openshift-ci

openshift-ci Bot commented Sep 8, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ehearne-redhat, jubittajohn

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 8, 2026
@ehearne-redhat

Copy link
Copy Markdown
Author

/test e2e-aws-ovn-hypershift

@ehearne-redhat

Copy link
Copy Markdown
Author

/retest-required

@jubittajohn

Copy link
Copy Markdown

/test e2e-aws-ovn-hypershift

1 similar comment
@ehearne-redhat

Copy link
Copy Markdown
Author

/test e2e-aws-ovn-hypershift

@openshift-ci

openshift-ci Bot commented Sep 10, 2026

Copy link
Copy Markdown

@ehearne-redhat: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/perfscale-control-plane-6nodes b9c17c8 link false /test perfscale-control-plane-6nodes

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@ehearne-redhat

Copy link
Copy Markdown
Author

/test e2e-aws-ovn-hypershift

@jubittajohn

Copy link
Copy Markdown

/verified by ci

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Sep 11, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@jubittajohn: This PR has been marked as verified by ci.

Details

In response to this:

/verified by ci

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-merge-bot
openshift-merge-bot Bot merged commit b376ee7 into openshift:release-5.0 Sep 11, 2026
20 of 21 checks passed
@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: Jira Issue Verification Checks: Jira Issue OCPBUGS-108014
✔️ This pull request was pre-merge verified.
✔️ All associated pull requests have merged.
✔️ All associated, merged pull requests were pre-merge verified.

Jira Issue OCPBUGS-108014 has been moved to the MODIFIED state and will move to the VERIFIED state when the change is available in an accepted nightly payload. 🕓

Details

In response to this:

This change bumps otel to v1.44.0 across the kubernetes repo. It also updates transient dependencies where necessary.

See https://pkg.go.dev/vuln/GO-2026-5158 for reference.

Keeping this change in release-5.0 to respect 1.37 kube rebase to land in master and release-5.1.

See #2738 for reference.

Also see kubernetes#139380 for reference.
Since release-5.0 is pinned to kube 1.36, this change is necessary as only 1.37+ kubernetes will get this patch for free.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@rissh

rissh commented Sep 11, 2026

Copy link
Copy Markdown

/retitle [release-5.0] OCPBUGS-108014,OCPBUGS-107890,OCPBUGS-107915: UPSTREAM: : bump otel to v1.44.0 to fix CVE-2026-41178

@openshift-ci openshift-ci Bot changed the title [release-5.0] OCPBUGS-108014: UPSTREAM: <carry>: bump otel to v1.44.0 to fix CVE-2026-41178 [release-5.0] OCPBUGS-108014,OCPBUGS-107890,OCPBUGS-107915: UPSTREAM: <carry>: bump otel to v1.44.0 to fix CVE-2026-41178 Sep 11, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@ehearne-redhat: Jira Issue OCPBUGS-108014 is in an unrecognized state (ON_QA) and will not be moved to the MODIFIED state.

Jira Issue Verification Checks: Jira Issue OCPBUGS-107890
✔️ This pull request was pre-merge verified.
✔️ All associated pull requests have merged.
✔️ All associated, merged pull requests were pre-merge verified.

Jira Issue OCPBUGS-107890 has been moved to the MODIFIED state and will move to the VERIFIED state when the change is available in an accepted nightly payload. 🕓

Jira Issue Verification Checks: Jira Issue OCPBUGS-107915
✔️ This pull request was pre-merge verified.
✔️ All associated pull requests have merged.
✔️ All associated, merged pull requests were pre-merge verified.

Jira Issue OCPBUGS-107915 has been moved to the MODIFIED state and will move to the VERIFIED state when the change is available in an accepted nightly payload. 🕓

Details

In response to this:

This change bumps otel to v1.44.0 across the kubernetes repo. It also updates transient dependencies where necessary.

See https://pkg.go.dev/vuln/GO-2026-5158 for reference.

Keeping this change in release-5.0 to respect 1.37 kube rebase to land in master and release-5.1.

See #2738 for reference.

Also see kubernetes#139380 for reference.
Since release-5.0 is pinned to kube 1.36, this change is necessary as only 1.37+ kubernetes will get this patch for free.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-merge-robot

Copy link
Copy Markdown

Fix included in release 5.0.0-0.nightly-2026-09-12-234912

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. backport-risk-assessed Indicates a PR to a release branch has been evaluated and considered safe to accept. jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. vendor-update Touching vendor dir or related files verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants