Skip to content

Improve InetSocketAddress deserialization [CVE-2026-54514] - #5951

Merged
cowtowncoder merged 5 commits into
2.18from
tatu/2.18/inet-socket-addr-deser
May 6, 2026
Merged

cowtowncoder merged 5 commits into
2.18from
tatu/2.18/inet-socket-addr-deser

Conversation

@cowtowncoder

@cowtowncoder cowtowncoder commented May 5, 2026 •

Copy link
Copy Markdown
Member

Should create "unresolved" instances to avoid DNS lookup.

@cowtowncoder cowtowncoder added the 2.18 Issues planned at 2.18 or later label May 5, 2026
@cowtowncoder cowtowncoder added this to the 2.18.8 milestone May 5, 2026
@cowtowncoder
cowtowncoder marked this pull request as ready for review May 6, 2026 00:01
@cowtowncoder
cowtowncoder merged commit 1f5a103 into 2.18 May 6, 2026
5 of 6 checks passed
@cowtowncoder
cowtowncoder deleted the tatu/2.18/inet-socket-addr-deser branch May 6, 2026 00:09
dongjoon-hyun added a commit to apache/spark that referenced this pull request Jun 5, 2026
### What changes were proposed in this pull request?

This PR upgrades `FasterXML` `Jackson` to 2.21.4.

### Why are the changes needed?

- https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.21.4 (2026-05-28)
  - FasterXML/jackson-core#1611
  - FasterXML/jackson-databind#5931
  - FasterXML/jackson-databind#5950
  - FasterXML/jackson-databind#5951
  - FasterXML/jackson-databind#5967
  - FasterXML/jackson-databind#5969
  - FasterXML/jackson-databind#5971
  - FasterXML/jackson-databind#5974
  - FasterXML/jackson-databind#5981
  - FasterXML/jackson-databind#5988
  - FasterXML/jackson-databind#5993

### Does this PR introduce _any_ user-facing change?

No.

### How was this patch tested?

Pass the CIs.

### Was this patch authored or co-authored using generative AI tooling?

Generated-by: Claude Code (Claude Opus 4.8)

Closes #56338 from dongjoon-hyun/SPARK-57273.

Authored-by: Dongjoon Hyun <dongjoon@apache.org>
Signed-off-by: Dongjoon Hyun <dongjoon@apache.org>
@cowtowncoder cowtowncoder changed the title Improve InetSocketAddress deserialization Improve InetSocketAddress deserialization [CVE-2026-54514] Jun 16, 2026
@cowtowncoder cowtowncoder added 2.21 3.1 CVE Issues related to public CVEs (security vuln reports) labels Jun 16, 2026
cowtowncoder added a commit that referenced this pull request Jun 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

2.18 Issues planned at 2.18 or later 2.21 3.1 CVE Issues related to public CVEs (security vuln reports)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant