diff --git a/sdk_container/src/third_party/coreos-overlay/coreos/user-patches/sys-libs/libcap/0001-pam-cap-Fix-potential-configuration-parsing-error.patch b/sdk_container/src/third_party/coreos-overlay/coreos/user-patches/sys-libs/libcap/0001-pam-cap-Fix-potential-configuration-parsing-error.patch deleted file mode 100644 index 839aed2ccc..0000000000 --- a/sdk_container/src/third_party/coreos-overlay/coreos/user-patches/sys-libs/libcap/0001-pam-cap-Fix-potential-configuration-parsing-error.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 1ad42b66c3567481cc5fa22fc1ba1556a316d878 Mon Sep 17 00:00:00 2001 -From: Tianjia Zhang -Date: Mon, 17 Feb 2025 10:31:55 +0800 -Subject: pam_cap: Fix potential configuration parsing error - -The current configuration parsing does not actually skip user names -that do not start with @, but instead treats the name as a group -name for further parsing, which can result in matching unexpected -capability sets and may trigger potential security issues. Only -names starting with @ should be parsed as group names. - -Signed-off-by: Tianjia Zhang -Signed-off-by: Andrew G. Morgan ---- - pam_cap/pam_cap.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/pam_cap/pam_cap.c b/pam_cap/pam_cap.c -index 24de329..3ec99bb 100644 ---- a/pam_cap/pam_cap.c -+++ b/pam_cap/pam_cap.c -@@ -166,6 +166,7 @@ static char *read_capabilities_for_user(const char *user, const char *source) - - if (line[0] != '@') { - D(("user [%s] is not [%s] - skipping", user, line)); -+ continue; - } - - int i; --- -cgit 1.2.3-korg - diff --git a/sdk_container/src/third_party/coreos-overlay/coreos/user-patches/sys-libs/libcap/README.md b/sdk_container/src/third_party/coreos-overlay/coreos/user-patches/sys-libs/libcap/README.md deleted file mode 100644 index a931f4f466..0000000000 --- a/sdk_container/src/third_party/coreos-overlay/coreos/user-patches/sys-libs/libcap/README.md +++ /dev/null @@ -1,3 +0,0 @@ -The `0001-pam-cap-Fix-potential-configuration-parsing-error.patch` -patch addresses CVE-2025-1390. It can be dropped when updating to -2.74.