Skip to content

Refresh RPM lockfiles [SECURITY] - #4375

Open
red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
mainfrom
renovate/main/lock-file-maintenance-vulnerability
Open

Refresh RPM lockfiles [SECURITY]#4375
red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
mainfrom
renovate/main/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux-kflux-prd-rh03

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot commented Nov 19, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
python3-idna 3.10-6.fc43 -> 3.18-1.fc43
awscli2 2.35.0-1.fc43 -> 2.36.0-1.fc43
bat 0.26.1-1.fc43 -> 0.26.1-3.fc43
bootc 1.16.3-1.fc43 -> 1.16.7-1.fc43
cpp 15.2.1-7.fc43 -> 15.3.1-1.fc43
cryptsetup 2.8.4-1.fc43 -> 2.8.7-1.fc43
cryptsetup-libs 2.8.4-1.fc43 -> 2.8.7-1.fc43
distribution-gpg-keys 1.119-1.fc43 -> 1.120-1.fc43
edk2-aarch64 20260508-4.fc43 -> 20260508-5.fc43
edk2-ovmf 20260508-4.fc43 -> 20260508-5.fc43
edk2-shell-aa64 20260508-4.fc43 -> 20260508-5.fc43
edk2-shell-x64 20260508-4.fc43 -> 20260508-5.fc43
gcc 15.2.1-7.fc43 -> 15.3.1-1.fc43
gcc-plugin-annobin 15.2.1-7.fc43 -> 15.3.1-1.fc43
hwdata 0.409-1.fc43 -> 0.410-1.fc43
kernel-core 7.1.4-104.fc43 -> 7.1.8-100.fc43
kernel-modules 7.1.4-104.fc43 -> 7.1.8-100.fc43
kernel-modules-core 7.1.4-104.fc43 -> 7.1.8-100.fc43
libldb 2:4.23.9-1.fc43 -> 2:4.23.10-1.fc43
libnbd 1.24.2-1.fc43 -> 1.24.3-1.fc43
librados2 2:19.2.4-1.fc43 -> 2:19.2.5-1.fc43
librbd1 2:19.2.4-1.fc43 -> 2:19.2.5-1.fc43
libsmbclient 2:4.23.9-1.fc43 -> 2:4.23.10-1.fc43
libwbclient 2:4.23.9-1.fc43 -> 2:4.23.10-1.fc43
llvm-filesystem 21.1.8-4.fc43 -> 21.1.8-6.fc43
llvm-libs 21.1.8-4.fc43 -> 21.1.8-6.fc43
mbedtls 3.6.6-2.fc43 -> 3.6.7-1.fc43
nspr 4.39.0-2.fc43 -> 4.39.0-3.fc43
nss 3.125.0-1.fc43 -> 3.126.0-1.fc43
nss-softokn 3.125.0-1.fc43 -> 3.126.0-1.fc43
nss-softokn-freebl 3.125.0-1.fc43 -> 3.126.0-1.fc43
nss-sysinit 3.125.0-1.fc43 -> 3.126.0-1.fc43
nss-util 3.125.0-1.fc43 -> 3.126.0-1.fc43
osbuild 185-1.fc43 -> 190-1.fc43
osbuild-initrd 185-1.fc43 -> 190-1.fc43
osbuild-ostree 185-1.fc43 -> 190-1.fc43
osbuild-selinux 185-1.fc43 -> 190-1.fc43
osbuild-tools 185-1.fc43 -> 190-1.fc43
passt 0^20260716.g090d739-2.fc43 -> 0^20260728.gf8df3f1-2.fc43
passt-selinux 0^20260716.g090d739-2.fc43 -> 0^20260728.gf8df3f1-2.fc43
perl-AutoLoader 5.74-523.fc43 -> 5.74-524.fc43
perl-B 1.89-523.fc43 -> 1.89-524.fc43
perl-Class-Struct 0.68-523.fc43 -> 0.68-524.fc43
perl-DynaLoader 1.57-523.fc43 -> 1.57-524.fc43
perl-Errno 1.38-523.fc43 -> 1.38-524.fc43
perl-Fcntl 1.20-523.fc43 -> 1.20-524.fc43
perl-File-Basename 2.86-523.fc43 -> 2.86-524.fc43
perl-File-Copy 2.41-523.fc43 -> 2.41-524.fc43
perl-File-stat 1.14-523.fc43 -> 1.14-524.fc43
perl-FileHandle 2.05-523.fc43 -> 2.05-524.fc43
perl-Getopt-Std 1.14-523.fc43 -> 1.14-524.fc43
perl-HTTP-Tiny 0.094-1.fc43 -> 0.096-1.fc43
perl-I18N-Langinfo 0.24-523.fc43 -> 0.24-524.fc43
perl-IO 1.55-523.fc43 -> 1.55-524.fc43
perl-IPC-Open3 1.24-523.fc43 -> 1.24-524.fc43
perl-NDBM_File 1.18-523.fc43 -> 1.18-524.fc43
perl-POSIX 2.23-523.fc43 -> 2.23-524.fc43
perl-SelectSaver 1.02-523.fc43 -> 1.02-524.fc43
perl-Symbol 1.09-523.fc43 -> 1.09-524.fc43
perl-base 2.27-523.fc43 -> 2.27-524.fc43
perl-if 0.61.000-523.fc43 -> 0.61.000-524.fc43
perl-interpreter 4:5.42.2-523.fc43 -> 4:5.42.3-524.fc43
perl-lib 0.65-523.fc43 -> 0.65-524.fc43
perl-libs 4:5.42.2-523.fc43 -> 4:5.42.3-524.fc43
perl-locale 1.13-523.fc43 -> 1.13-524.fc43
perl-mro 1.29-523.fc43 -> 1.29-524.fc43
perl-overload 1.40-523.fc43 -> 1.40-524.fc43
perl-overloading 0.02-523.fc43 -> 0.02-524.fc43
perl-vars 1.05-523.fc43 -> 1.05-524.fc43
pyproject-srpm-macros 1.22.2-1.fc43 -> 1.23.2-1.fc43
python3-audit 4.1.4-1.fc43 -> 4.2.1-1.fc43
python3-awscrt 0.34.1-1.fc43 -> 0.36.0-1.fc43
python3-boto3 1.43.51-1.fc43 -> 1.43.64-1.fc43
python3-botocore 1.43.51-1.fc43 -> 1.43.64-1.fc43
python3-osbuild 185-1.fc43 -> 190-1.fc43
python3-pyasn1 0.6.2-1.fc43 -> 0.6.4-1.fc43
python3-pyasn1-modules 0.6.2-1.fc43 -> 0.6.4-1.fc43
python3-rpm 6.0.1-1.fc43 -> 6.0.2-1.fc43
python3-unbound 1.25.1-1.fc43 -> 1.26.0-1.fc43
rpm-build 6.0.1-1.fc43 -> 6.0.2-1.fc43
rpm-plugin-selinux 6.0.1-1.fc43 -> 6.0.2-1.fc43
rpm-plugin-systemd-inhibit 6.0.1-1.fc43 -> 6.0.2-1.fc43
rust-srpm-macros 28.4-1.fc43 -> 28.5-1.fc43
samba-client-libs 2:4.23.9-1.fc43 -> 2:4.23.10-1.fc43
samba-common 2:4.23.9-1.fc43 -> 2:4.23.10-1.fc43
samba-common-libs 2:4.23.9-1.fc43 -> 2:4.23.10-1.fc43
selinux-policy 43.8-1.fc43 -> 43.9-1.fc43
selinux-policy-targeted 43.8-1.fc43 -> 43.9-1.fc43
skopeo 1:1.22.2-1.fc43 -> 1:1.22.2-2.fc43
systemd 258.9-1.fc43 -> 258.10-1.fc43
systemd-container 258.9-1.fc43 -> 258.10-1.fc43
systemd-networkd 258.9-1.fc43 -> 258.10-1.fc43
systemd-pam 258.9-1.fc43 -> 258.10-1.fc43
systemd-resolved 258.9-1.fc43 -> 258.10-1.fc43
systemd-rpm-macros 258.9-1.fc43 -> 258.10-1.fc43
systemd-shared 258.9-1.fc43 -> 258.10-1.fc43
systemd-udev 258.9-1.fc43 -> 258.10-1.fc43
unbound-anchor 1.25.1-1.fc43 -> 1.26.0-1.fc43
unbound-libs 1.25.1-1.fc43 -> 1.26.0-1.fc43
xen-libs 4.20.3-3.fc43 -> 4.20.4-1.fc43
xen-licenses 4.20.3-3.fc43 -> 4.20.4-1.fc43

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command

CVE-2026-44604

More information

Severity

Moderate

References


rpm: heap buffer overflow in NDB slot table parsing

CVE-2026-44605

More information

Severity

Low

References


unbound: Unbound: Denial of Service via excessive EDNS options

CVE-2026-41292

More information

Severity

Important

References


unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic

CVE-2026-42534

More information

Severity

Important

References


unbound: Unbound: Denial of Service due to excessive resource consumption with large DNS Resource Record Sets

CVE-2026-44390

More information

Severity

Important

References


unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments

CVE-2026-14586

More information

Severity

Important

References


unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length

CVE-2026-32665

More information

Severity

Important

References


unbound: Unbound: Denial of Service via crafted DNSCrypt query

CVE-2026-40691

More information

Severity

Important

References


unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries

CVE-2026-41637

More information

Severity

Important

References


unbound: Unbound: DNS cache integrity issue

CVE-2026-42955

More information

Severity

Important

References


unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes

CVE-2026-44690

More information

Severity

Important

References


unbound: Unbound: Information disclosure via DNSSEC wildcard replay

CVE-2026-46582

More information

Severity

Important

References


unbound: Unbound: Denial of Service via DNSSEC query amplification bypass

CVE-2026-50045

More information

Severity

Important

References


unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling

CVE-2026-50046

More information

Severity

Important

References


unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records

CVE-2026-50251

More information

Severity

Important

References


unbound: Unbound: Denial of service due to memory corruption under specific configurations.

CVE-2026-52863

More information

Severity

Important

References


unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation

CVE-2026-54478

More information

Severity

Important

References


unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option

CVE-2026-55973

More information

Severity

Important

References


unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration

CVE-2026-55990

More information

Severity

Important

References


unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection

CVE-2026-55991

More information

Severity

Important

References


unbound: Unbound: Heap buffer overflow via malformed DNSSEC record

CVE-2026-56416

More information

Severity

Important

References


unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration

CVE-2026-56444

More information

Severity

Important

References


unbound: Packet of death with DNSCrypt

CVE-2026-32792

More information

Severity

Moderate

References


unbound: Unbound: Cache manipulation via 'ghost domain names' attack

CVE-2026-40622

More information

Severity

Moderate

References


unbound: Unbound DNSSEC Validator NSEC3 Hash Calculation Limit Bypass via Negative Cache Code Path Leading to DoS

CVE-2026-42923

More information

Severity

Moderate

References


unbound: Unbound DNS Cache Poisoning via Promiscuous Additional Section RRSet Acceptance

CVE-2026-42960

More information

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 10 times, most recently from 0cc8577 to 2d3e298 Compare November 27, 2025 01:47
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 10 times, most recently from 97aa208 to c1ee429 Compare December 6, 2025 04:28
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 10 times, most recently from 1b727f7 to a65e124 Compare December 13, 2025 04:32
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 7 times, most recently from 1d277a5 to 395b4b7 Compare December 25, 2025 04:41
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 6 times, most recently from 0e6d162 to d9d8f95 Compare January 7, 2026 04:32
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 7 times, most recently from bebd0f6 to 04aa3d7 Compare January 14, 2026 04:44
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 6 times, most recently from 15821cf to 77d037a Compare January 18, 2026 04:50
jbtrystram
jbtrystram previously approved these changes Jun 3, 2026
Signed-off-by: red-hat-konflux-kflux-prd-rh03 <206760901+red-hat-konflux-kflux-prd-rh03[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant