Refresh RPM lockfiles [SECURITY] - #4375
Open
red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
Open
Refresh RPM lockfiles [SECURITY]#4375red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
Conversation
red-hat-konflux-kflux-prd-rh03
Bot
force-pushed
the
renovate/main/lock-file-maintenance-vulnerability
branch
10 times, most recently
from
November 27, 2025 01:47
0cc8577 to
2d3e298
Compare
red-hat-konflux-kflux-prd-rh03
Bot
force-pushed
the
renovate/main/lock-file-maintenance-vulnerability
branch
10 times, most recently
from
December 6, 2025 04:28
97aa208 to
c1ee429
Compare
red-hat-konflux-kflux-prd-rh03
Bot
force-pushed
the
renovate/main/lock-file-maintenance-vulnerability
branch
10 times, most recently
from
December 13, 2025 04:32
1b727f7 to
a65e124
Compare
red-hat-konflux-kflux-prd-rh03
Bot
force-pushed
the
renovate/main/lock-file-maintenance-vulnerability
branch
7 times, most recently
from
December 25, 2025 04:41
1d277a5 to
395b4b7
Compare
red-hat-konflux-kflux-prd-rh03
Bot
force-pushed
the
renovate/main/lock-file-maintenance-vulnerability
branch
6 times, most recently
from
January 7, 2026 04:32
0e6d162 to
d9d8f95
Compare
red-hat-konflux-kflux-prd-rh03
Bot
force-pushed
the
renovate/main/lock-file-maintenance-vulnerability
branch
7 times, most recently
from
January 14, 2026 04:44
bebd0f6 to
04aa3d7
Compare
red-hat-konflux-kflux-prd-rh03
Bot
force-pushed
the
renovate/main/lock-file-maintenance-vulnerability
branch
6 times, most recently
from
January 18, 2026 04:50
15821cf to
77d037a
Compare
This was referenced Mar 18, 2026
jbtrystram
previously approved these changes
Jun 3, 2026
Signed-off-by: red-hat-konflux-kflux-prd-rh03 <206760901+red-hat-konflux-kflux-prd-rh03[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
File rpms.in.yaml:
3.10-6.fc43->3.18-1.fc432.35.0-1.fc43->2.36.0-1.fc430.26.1-1.fc43->0.26.1-3.fc431.16.3-1.fc43->1.16.7-1.fc4315.2.1-7.fc43->15.3.1-1.fc432.8.4-1.fc43->2.8.7-1.fc432.8.4-1.fc43->2.8.7-1.fc431.119-1.fc43->1.120-1.fc4320260508-4.fc43->20260508-5.fc4320260508-4.fc43->20260508-5.fc4320260508-4.fc43->20260508-5.fc4320260508-4.fc43->20260508-5.fc4315.2.1-7.fc43->15.3.1-1.fc4315.2.1-7.fc43->15.3.1-1.fc430.409-1.fc43->0.410-1.fc437.1.4-104.fc43->7.1.8-100.fc437.1.4-104.fc43->7.1.8-100.fc437.1.4-104.fc43->7.1.8-100.fc432:4.23.9-1.fc43->2:4.23.10-1.fc431.24.2-1.fc43->1.24.3-1.fc432:19.2.4-1.fc43->2:19.2.5-1.fc432:19.2.4-1.fc43->2:19.2.5-1.fc432:4.23.9-1.fc43->2:4.23.10-1.fc432:4.23.9-1.fc43->2:4.23.10-1.fc4321.1.8-4.fc43->21.1.8-6.fc4321.1.8-4.fc43->21.1.8-6.fc433.6.6-2.fc43->3.6.7-1.fc434.39.0-2.fc43->4.39.0-3.fc433.125.0-1.fc43->3.126.0-1.fc433.125.0-1.fc43->3.126.0-1.fc433.125.0-1.fc43->3.126.0-1.fc433.125.0-1.fc43->3.126.0-1.fc433.125.0-1.fc43->3.126.0-1.fc43185-1.fc43->190-1.fc43185-1.fc43->190-1.fc43185-1.fc43->190-1.fc43185-1.fc43->190-1.fc43185-1.fc43->190-1.fc430^20260716.g090d739-2.fc43->0^20260728.gf8df3f1-2.fc430^20260716.g090d739-2.fc43->0^20260728.gf8df3f1-2.fc435.74-523.fc43->5.74-524.fc431.89-523.fc43->1.89-524.fc430.68-523.fc43->0.68-524.fc431.57-523.fc43->1.57-524.fc431.38-523.fc43->1.38-524.fc431.20-523.fc43->1.20-524.fc432.86-523.fc43->2.86-524.fc432.41-523.fc43->2.41-524.fc431.14-523.fc43->1.14-524.fc432.05-523.fc43->2.05-524.fc431.14-523.fc43->1.14-524.fc430.094-1.fc43->0.096-1.fc430.24-523.fc43->0.24-524.fc431.55-523.fc43->1.55-524.fc431.24-523.fc43->1.24-524.fc431.18-523.fc43->1.18-524.fc432.23-523.fc43->2.23-524.fc431.02-523.fc43->1.02-524.fc431.09-523.fc43->1.09-524.fc432.27-523.fc43->2.27-524.fc430.61.000-523.fc43->0.61.000-524.fc434:5.42.2-523.fc43->4:5.42.3-524.fc430.65-523.fc43->0.65-524.fc434:5.42.2-523.fc43->4:5.42.3-524.fc431.13-523.fc43->1.13-524.fc431.29-523.fc43->1.29-524.fc431.40-523.fc43->1.40-524.fc430.02-523.fc43->0.02-524.fc431.05-523.fc43->1.05-524.fc431.22.2-1.fc43->1.23.2-1.fc434.1.4-1.fc43->4.2.1-1.fc430.34.1-1.fc43->0.36.0-1.fc431.43.51-1.fc43->1.43.64-1.fc431.43.51-1.fc43->1.43.64-1.fc43185-1.fc43->190-1.fc430.6.2-1.fc43->0.6.4-1.fc430.6.2-1.fc43->0.6.4-1.fc436.0.1-1.fc43->6.0.2-1.fc431.25.1-1.fc43->1.26.0-1.fc436.0.1-1.fc43->6.0.2-1.fc436.0.1-1.fc43->6.0.2-1.fc436.0.1-1.fc43->6.0.2-1.fc4328.4-1.fc43->28.5-1.fc432:4.23.9-1.fc43->2:4.23.10-1.fc432:4.23.9-1.fc43->2:4.23.10-1.fc432:4.23.9-1.fc43->2:4.23.10-1.fc4343.8-1.fc43->43.9-1.fc4343.8-1.fc43->43.9-1.fc431:1.22.2-1.fc43->1:1.22.2-2.fc43258.9-1.fc43->258.10-1.fc43258.9-1.fc43->258.10-1.fc43258.9-1.fc43->258.10-1.fc43258.9-1.fc43->258.10-1.fc43258.9-1.fc43->258.10-1.fc43258.9-1.fc43->258.10-1.fc43258.9-1.fc43->258.10-1.fc43258.9-1.fc43->258.10-1.fc431.25.1-1.fc43->1.26.0-1.fc431.25.1-1.fc43->1.26.0-1.fc434.20.3-3.fc43->4.20.4-1.fc434.20.3-3.fc43->4.20.4-1.fc43Warning
Some dependencies could not be looked up. Check the warning logs for more information.
rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command
CVE-2026-44604
More information
Severity
Moderate
References
rpm: heap buffer overflow in NDB slot table parsing
CVE-2026-44605
More information
Severity
Low
References
unbound: Unbound: Denial of Service via excessive EDNS options
CVE-2026-41292
More information
Severity
Important
References
unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic
CVE-2026-42534
More information
Severity
Important
References
unbound: Unbound: Denial of Service due to excessive resource consumption with large DNS Resource Record Sets
CVE-2026-44390
More information
Severity
Important
References
unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments
CVE-2026-14586
More information
Severity
Important
References
unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length
CVE-2026-32665
More information
Severity
Important
References
unbound: Unbound: Denial of Service via crafted DNSCrypt query
CVE-2026-40691
More information
Severity
Important
References
unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries
CVE-2026-41637
More information
Severity
Important
References
unbound: Unbound: DNS cache integrity issue
CVE-2026-42955
More information
Severity
Important
References
unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes
CVE-2026-44690
More information
Severity
Important
References
unbound: Unbound: Information disclosure via DNSSEC wildcard replay
CVE-2026-46582
More information
Severity
Important
References
unbound: Unbound: Denial of Service via DNSSEC query amplification bypass
CVE-2026-50045
More information
Severity
Important
References
unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling
CVE-2026-50046
More information
Severity
Important
References
unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records
CVE-2026-50251
More information
Severity
Important
References
unbound: Unbound: Denial of service due to memory corruption under specific configurations.
CVE-2026-52863
More information
Severity
Important
References
unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation
CVE-2026-54478
More information
Severity
Important
References
unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option
CVE-2026-55973
More information
Severity
Important
References
unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration
CVE-2026-55990
More information
Severity
Important
References
unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection
CVE-2026-55991
More information
Severity
Important
References
unbound: Unbound: Heap buffer overflow via malformed DNSSEC record
CVE-2026-56416
More information
Severity
Important
References
unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
CVE-2026-56444
More information
Severity
Important
References
unbound: Packet of death with DNSCrypt
CVE-2026-32792
More information
Severity
Moderate
References
unbound: Unbound: Cache manipulation via 'ghost domain names' attack
CVE-2026-40622
More information
Severity
Moderate
References
unbound: Unbound DNSSEC Validator NSEC3 Hash Calculation Limit Bypass via Negative Cache Code Path Leading to DoS
CVE-2026-42923
More information
Severity
Moderate
References
unbound: Unbound DNS Cache Poisoning via Promiscuous Additional Section RRSet Acceptance
CVE-2026-42960
More information
Severity
Moderate
References
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.