Skip to content

Refresh RPM lockfiles [SECURITY]#257

Open
red-hat-konflux[bot] wants to merge 1 commit into
alphafrom
konflux/mintmaker/alpha/lock-file-maintenance-vulnerability
Open

Refresh RPM lockfiles [SECURITY]#257
red-hat-konflux[bot] wants to merge 1 commit into
alphafrom
konflux/mintmaker/alpha/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Oct 8, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
annobin 12.92-1.el9 -> 12.98-1.el9
cargo 1.84.1-1.el9 -> 1.88.0-1.el9
clang 19.1.7-2.el9 -> 20.1.8-3.el9
clang-libs 19.1.7-2.el9 -> 20.1.8-3.el9
clang-resource-filesystem 19.1.7-2.el9 -> 20.1.8-3.el9
compiler-rt 19.1.7-2.el9 -> 20.1.8-3.el9
containers-common 2:1-117.el9_6 -> 4:1-135.el9_7
cpp 11.5.0-5.el9_5 -> 11.5.0-11.el9
criu 3.19-1.el9 -> 3.19-3.el9
criu-libs 3.19-1.el9 -> 3.19-3.el9
crun 1.21-1.el9_6 -> 1.23.1-2.el9_7
dwz 0.14-3.el9 -> 0.16-1.el9
efi-srpm-macros 6-2.el9_0 -> 6-4.el9
emacs-filesystem 1:27.2-13.el9_6 -> 1:27.2-18.el9
fuse-overlayfs 1.14-1.el9 -> 1.16-1.el9_7
gcc 11.5.0-5.el9_5 -> 11.5.0-11.el9
gcc-c++ 11.5.0-5.el9_5 -> 11.5.0-11.el9
gcc-plugin-annobin 11.5.0-5.el9_5 -> 11.5.0-11.el9
gcc-toolset-14-binutils 2.41-3.el9 -> 2.41-5.el9_7.1
gcc-toolset-14-gcc 14.2.1-7.1.el9 -> 14.2.1-12.el9_7
gcc-toolset-14-gcc-c++ 14.2.1-7.1.el9 -> 14.2.1-12.el9_7
gcc-toolset-14-libstdc++-devel 14.2.1-7.1.el9 -> 14.2.1-12.el9_7
gcc-toolset-14-runtime 14.0-1.el9 -> 14.0-2.el9
git 2.47.1-2.el9_6 -> 2.47.3-1.el9_6
git-core 2.47.1-2.el9_6 -> 2.47.3-1.el9_6
git-core-doc 2.47.1-2.el9_6 -> 2.47.3-1.el9_6
glibc-devel 2.34-168.el9_6.19 -> 2.34-231.el9_7.10
glibc-headers 2.34-168.el9_6.19 -> 2.34-231.el9_7.10
go-srpm-macros 3.6.0-10.el9_6 -> 3.6.0-13.el9_7
kernel-headers 5.14.0-570.22.1.el9_6 -> 5.14.0-611.38.1.el9_7
kernel-srpm-macros 1.0-13.el9 -> 1.0-14.el9
libomp 19.1.7-2.el9 -> 20.1.8-3.el9
libomp-devel 19.1.7-2.el9 -> 20.1.8-3.el9
libstdc++-devel 11.5.0-5.el9_5 -> 11.5.0-11.el9
lld 19.1.7-2.el9 -> 20.1.8-3.el9
lld-libs 19.1.7-2.el9 -> 20.1.8-3.el9
llvm 19.1.7-2.el9 -> 20.1.8-3.el9
llvm-libs 19.1.7-2.el9 -> 20.1.8-3.el9
llvm-toolset 19.1.7-2.el9 -> 20.1.8-3.el9
nginx 2:1.20.1-22.el9_6.2 -> 2:1.20.1-22.el9_6.3
nginx-core 2:1.20.1-22.el9_6.2 -> 2:1.20.1-22.el9_6.3
nginx-filesystem 2:1.20.1-22.el9_6.2 -> 2:1.20.1-22.el9_6.3
openssl-devel 1:3.2.2-6.el9_5.1 -> 1:3.5.1-7.el9_7
perl 4:5.32.1-481.el9 -> 4:5.32.1-481.1.el9_6
perl-Attribute-Handlers 1.01-481.el9 -> 1.01-481.1.el9_6
perl-AutoLoader 5.74-481.el9 -> 5.74-481.1.el9_6
perl-AutoSplit 5.74-481.el9 -> 5.74-481.1.el9_6
perl-B 1.80-481.el9 -> 1.80-481.1.el9_6
perl-Benchmark 1.23-481.el9 -> 1.23-481.1.el9_6
perl-Class-Struct 0.66-481.el9 -> 0.66-481.1.el9_6
perl-Config-Extensions 0.03-481.el9 -> 0.03-481.1.el9_6
perl-DBM_Filter 0.06-481.el9 -> 0.06-481.1.el9_6
perl-Devel-Peek 1.28-481.el9 -> 1.28-481.1.el9_6
perl-Devel-SelfStubber 1.06-481.el9 -> 1.06-481.1.el9_6
perl-DirHandle 1.05-481.el9 -> 1.05-481.1.el9_6
perl-Dumpvalue 2.27-481.el9 -> 2.27-481.1.el9_6
perl-DynaLoader 1.47-481.el9 -> 1.47-481.1.el9_6
perl-English 1.11-481.el9 -> 1.11-481.1.el9_6
perl-Errno 1.30-481.el9 -> 1.30-481.1.el9_6
perl-ExtUtils-Constant 0.25-481.el9 -> 0.25-481.1.el9_6
perl-ExtUtils-Embed 1.35-481.el9 -> 1.35-481.1.el9_6
perl-ExtUtils-Miniperl 1.09-481.el9 -> 1.09-481.1.el9_6
perl-Fcntl 1.13-481.el9 -> 1.13-481.1.el9_6
perl-File-Basename 2.85-481.el9 -> 2.85-481.1.el9_6
perl-File-Compare 1.100.600-481.el9 -> 1.100.600-481.1.el9_6
perl-File-Copy 2.34-481.el9 -> 2.34-481.1.el9_6
perl-File-DosGlob 1.12-481.el9 -> 1.12-481.1.el9_6
perl-File-Find 1.37-481.el9 -> 1.37-481.1.el9_6
perl-File-stat 1.09-481.el9 -> 1.09-481.1.el9_6
perl-FileCache 1.10-481.el9 -> 1.10-481.1.el9_6
perl-FileHandle 2.03-481.el9 -> 2.03-481.1.el9_6
perl-FindBin 1.51-481.el9 -> 1.51-481.1.el9_6
perl-GDBM_File 1.18-481.el9 -> 1.18-481.1.el9_6
perl-Getopt-Std 1.12-481.el9 -> 1.12-481.1.el9_6
perl-Git 2.47.1-2.el9_6 -> 2.47.3-1.el9_6
perl-Hash-Util 0.23-481.el9 -> 0.23-481.1.el9_6
perl-Hash-Util-FieldHash 1.20-481.el9 -> 1.20-481.1.el9_6
perl-I18N-Collate 1.02-481.el9 -> 1.02-481.1.el9_6
perl-I18N-LangTags 0.44-481.el9 -> 0.44-481.1.el9_6
perl-I18N-Langinfo 0.19-481.el9 -> 0.19-481.1.el9_6
perl-IO 1.43-481.el9 -> 1.43-481.1.el9_6
perl-IPC-Open3 1.21-481.el9 -> 1.21-481.1.el9_6
perl-Locale-Maketext-Simple 1:0.21-481.el9 -> 1:0.21-481.1.el9_6
perl-Math-Complex 1.59-481.el9 -> 1.59-481.1.el9_6
perl-Memoize 1.03-481.el9 -> 1.03-481.1.el9_6
perl-Module-Loaded 1:0.08-481.el9 -> 1:0.08-481.1.el9_6
perl-NDBM_File 1.15-481.el9 -> 1.15-481.1.el9_6
perl-NEXT 0.67-481.el9 -> 0.67-481.1.el9_6
perl-Net 1.02-481.el9 -> 1.02-481.1.el9_6
perl-Net-SSLeay 1.94-1.el9 -> 1.94-3.el9
perl-ODBM_File 1.16-481.el9 -> 1.16-481.1.el9_6
perl-Opcode 1.48-481.el9 -> 1.48-481.1.el9_6
perl-POSIX 1.94-481.el9 -> 1.94-481.1.el9_6
perl-Pod-Functions 1.13-481.el9 -> 1.13-481.1.el9_6
perl-Pod-Html 1.25-481.el9 -> 1.25-481.1.el9_6
perl-Safe 2.41-481.el9 -> 2.41-481.1.el9_6
perl-Search-Dict 1.07-481.el9 -> 1.07-481.1.el9_6
perl-SelectSaver 1.02-481.el9 -> 1.02-481.1.el9_6
perl-SelfLoader 1.26-481.el9 -> 1.26-481.1.el9_6
perl-Symbol 1.08-481.el9 -> 1.08-481.1.el9_6
perl-Sys-Hostname 1.23-481.el9 -> 1.23-481.1.el9_6
perl-Term-Complete 1.403-481.el9 -> 1.403-481.1.el9_6
perl-Term-ReadLine 1.17-481.el9 -> 1.17-481.1.el9_6
perl-Test 1.31-481.el9 -> 1.31-481.1.el9_6
perl-Text-Abbrev 1.02-481.el9 -> 1.02-481.1.el9_6
perl-Thread 3.05-481.el9 -> 3.05-481.1.el9_6
perl-Thread-Semaphore 2.13-481.el9 -> 2.13-481.1.el9_6
perl-Tie 4.6-481.el9 -> 4.6-481.1.el9_6
perl-Tie-File 1.06-481.el9 -> 1.06-481.1.el9_6
perl-Tie-Memoize 1.1-481.el9 -> 1.1-481.1.el9_6
perl-Time 1.03-481.el9 -> 1.03-481.1.el9_6
perl-Time-Piece 1.3401-481.el9 -> 1.3401-481.1.el9_6
perl-Unicode-UCD 0.75-481.el9 -> 0.75-481.1.el9_6
perl-User-pwent 1.03-481.el9 -> 1.03-481.1.el9_6
perl-autouse 1.11-481.el9 -> 1.11-481.1.el9_6
perl-base 2.27-481.el9 -> 2.27-481.1.el9_6
perl-blib 1.07-481.el9 -> 1.07-481.1.el9_6
perl-debugger 1.56-481.el9 -> 1.56-481.1.el9_6
perl-deprecate 0.04-481.el9 -> 0.04-481.1.el9_6
perl-devel 4:5.32.1-481.el9 -> 4:5.32.1-481.1.el9_6
perl-diagnostics 1.37-481.el9 -> 1.37-481.1.el9_6
perl-doc 5.32.1-481.el9 -> 5.32.1-481.1.el9_6
perl-encoding-warnings 0.13-481.el9 -> 0.13-481.1.el9_6
perl-fields 2.27-481.el9 -> 2.27-481.1.el9_6
perl-filetest 1.03-481.el9 -> 1.03-481.1.el9_6
perl-if 0.60.800-481.el9 -> 0.60.800-481.1.el9_6
perl-interpreter 4:5.32.1-481.el9 -> 4:5.32.1-481.1.el9_6
perl-less 0.03-481.el9 -> 0.03-481.1.el9_6
perl-lib 0.65-481.el9 -> 0.65-481.1.el9_6
perl-libnetcfg 4:5.32.1-481.el9 -> 4:5.32.1-481.1.el9_6
perl-libs 4:5.32.1-481.el9 -> 4:5.32.1-481.1.el9_6
perl-locale 1.09-481.el9 -> 1.09-481.1.el9_6
perl-macros 4:5.32.1-481.el9 -> 4:5.32.1-481.1.el9_6
perl-meta-notation 5.32.1-481.el9 -> 5.32.1-481.1.el9_6
perl-mro 1.23-481.el9 -> 1.23-481.1.el9_6
perl-open 1.12-481.el9 -> 1.12-481.1.el9_6
perl-overload 1.31-481.el9 -> 1.31-481.1.el9_6
perl-overloading 0.02-481.el9 -> 0.02-481.1.el9_6
perl-ph 5.32.1-481.el9 -> 5.32.1-481.1.el9_6
perl-sigtrap 1.09-481.el9 -> 1.09-481.1.el9_6
perl-sort 2.04-481.el9 -> 2.04-481.1.el9_6
perl-subs 1.03-481.el9 -> 1.03-481.1.el9_6
perl-utils 5.32.1-481.el9 -> 5.32.1-481.1.el9_6
perl-vars 1.05-481.el9 -> 1.05-481.1.el9_6
perl-vmsish 1.04-481.el9 -> 1.04-481.1.el9_6
policycoreutils-python-utils 3.6-2.1.el9 -> 3.6-3.el9
python3-audit 3.1.5-4.el9 -> 3.1.5-7.el9
python3-policycoreutils 3.6-2.1.el9 -> 3.6-3.el9
redhat-logos-httpd 90.4-2.el9 -> 90.5-1.el9_6.1
redhat-rpm-config 209-1.el9 -> 210-1.el9
rust 1.84.1-1.el9 -> 1.88.0-1.el9
rust-std-static 1.84.1-1.el9 -> 1.88.0-1.el9
rust-toolset 1.84.1-1.el9 -> 1.88.0-1.el9
skopeo 2:1.18.1-2.el9_6 -> 2:1.20.0-3.el9_7
slirp4netns 1.3.2-1.el9 -> 1.3.3-1.el9
systemtap-sdt-devel 5.2-2.el9 -> 5.3-3.el9
binutils 2.35.2-63.el9 -> 2.35.2-67.el9_7.1
binutils-gold 2.35.2-63.el9 -> 2.35.2-67.el9_7.1
elfutils-debuginfod-client 0.192-5.el9 -> 0.193-1.el9
environment-modules 5.3.0-1.el9 -> 5.3.0-2.el9
glibc-gconv-extra 2.34-168.el9_6.19 -> 2.34-231.el9_7.10
kmod 28-10.el9 -> 28-11.el9
less 590-5.el9 -> 590-6.el9
libatomic 11.5.0-5.el9_5 -> 11.5.0-11.el9
libbrotli 1.0.9-7.el9_5 -> 1.0.9-9.el9_7
logrotate 3.18.0-9.el9 -> 3.18.0-12.el9
man-db 2.9.3-7.el9 -> 2.9.3-9.el9
ncurses 6.2-10.20210508.el9 -> 6.2-12.20210508.el9
openssh 8.7p1-45.el9 -> 8.7p1-47.el9_7
openssh-clients 8.7p1-45.el9 -> 8.7p1-47.el9_7
policycoreutils 3.6-2.1.el9 -> 3.6-3.el9
shadow-utils-subid 2:4.9-12.el9 -> 2:4.9-15.el9
unzip 6.0-58.el9_5 -> 6.0-59.el9
vim-filesystem 2:8.2.2637-22.el9_6 -> 2:8.2.2637-23.el9_7
protobuf 3.14.0-16.el9 -> 3.14.0-17.el9_7
rust-std-static-wasm32-unknown-unknown 1.84.1-1.el9 -> 1.88.0-1.el9
jq 1.6-17.el9 -> 1.6-19.el9
protobuf-compiler 3.14.0-16.el9 -> 3.14.0-17.el9_7
protobuf-devel 3.14.0-16.el9 -> 3.14.0-17.el9_7

binutils: GNU Binutils Linker heap-based overflow

CVE-2025-11083

More information

Details

A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".

Severity

Moderate

References


glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

CVE-2025-15281

More information

Details

A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.

Severity

Moderate

References


glibc: glibc: Information disclosure via zero-valued network query

CVE-2026-0915

More information

Details

A flaw was found in glibc, the GNU C Library. When an application calls the getnetbyaddr or getnetbyaddr_r functions to resolve a network address, and the system's nsswitch.conf file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system.

Severity

Moderate

References


glibc: Integer overflow in memalign leads to heap corruption

CVE-2026-0861

More information

Details

A flaw was found in the glibc library. Passing an excessively large alignment value to the memalign suite of functions, such as memalign, posix_memalign, aligned_alloc, valloc and pvalloc, an integer overflow can occur during internal size calculations due to improper overflow checks, causing an allocation of a small chunk of memory which is subsequently used for writing. This issue can result in an application crash or heap memory corruption.

Severity

Moderate

References


os/exec: Unexpected paths returned from LookPath in os/exec

CVE-2025-47906

More information

Details

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

Severity

Moderate

References


golang: net/url: Memory exhaustion in query parameter parsing in net/url

CVE-2025-61726

More information

Details

A flaw was found in the net/url package in the Go standard library. The package does not enforce a limit on the number of unique query parameters it parses. A Go application using the net/http.Request.ParseForm method will try to process all parameters provided in the request. A specially crafted HTTP request containing a massive number of query parameters will cause the application to consume an excessive amount of memory, eventually causing the application to crash or become unresponsive, resulting in a denial of service.

Severity

Important

References


Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS

CVE-2025-6176

More information

Details

Scrapy are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.

Severity

Important

References


openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

CVE-2025-61984

More information

Details

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

Severity

Moderate

References


openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

CVE-2025-61985

More information

Details

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

Severity

Moderate

References


python: protobuf: Protobuf: Denial of Service due to recursion depth bypass

CVE-2026-0994

More information

Details

A flaw was found in protobuf. A remote attacker can exploit this denial-of-service (DoS) vulnerability by supplying deeply nested google.protobuf.Any messages to the google.protobuf.json_format.ParseDict() function. This bypasses the intended recursion depth limit, leading to the exhaustion of Python’s recursion stack and causing a RecursionError, which results in a denial of service.

Severity

Important

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 2 times, most recently from efdf0dd to 8de9ee7 Compare October 20, 2025 04:18
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 3 times, most recently from ee5d327 to 8d21661 Compare November 3, 2025 16:20
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 7 times, most recently from a559529 to ae6e123 Compare November 11, 2025 08:18
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 9 times, most recently from 8f3222d to aacbbe9 Compare November 17, 2025 12:20
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 3 times, most recently from 3d7dd05 to b1f055b Compare December 1, 2025 12:21
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 2 times, most recently from f1eb15b to 948fd66 Compare December 8, 2025 20:21
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch from 948fd66 to f4b0a7e Compare December 9, 2025 00:21
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 3 times, most recently from cafce85 to ad930ce Compare December 17, 2025 20:20
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 3 times, most recently from 91e2e66 to 90133c6 Compare January 12, 2026 16:20
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 2 times, most recently from 9b209b9 to 72f4091 Compare January 19, 2026 16:20
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 5 times, most recently from 121d437 to e9e0ab6 Compare February 2, 2026 04:18
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 4 times, most recently from 063ef31 to 0786b53 Compare February 10, 2026 12:22
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 6 times, most recently from d041053 to 1730a9e Compare February 23, 2026 12:22
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 5 times, most recently from 36181a7 to 8c1aae4 Compare March 2, 2026 04:20
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch 3 times, most recently from 002d46f to c20f23a Compare March 9, 2026 04:11
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/alpha/lock-file-maintenance-vulnerability branch from c20f23a to 8d26ab4 Compare March 9, 2026 12:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants