Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#3459

Merged
red-hat-konflux[bot] merged 1 commit into
masterfrom
konflux/mintmaker/master/lock-file-maintenance-vulnerability
Jul 22, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#3459
red-hat-konflux[bot] merged 1 commit into
masterfrom
konflux/mintmaker/master/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
glibc 2.34-272.el9_8 -> 2.34-274.el9_8
glibc-common 2.34-272.el9_8 -> 2.34-274.el9_8
glibc-gconv-extra 2.34-272.el9_8 -> 2.34-274.el9_8
glibc-minimal-langpack 2.34-272.el9_8 -> 2.34-274.el9_8
libacl 2.3.1-4.el9 -> 2.4.0-1.el9_8
libxml2 2.9.13-14.el9_8.1 -> 2.9.13-14.el9_8.2
openssl 1:3.5.5-4.el9_8 -> 1:3.5.5-5.el9_8
openssl-libs 1:3.5.5-4.el9_8 -> 1:3.5.5-5.el9_8

glibc: glibc: Out-of-bounds write via TSIG record processing

CVE-2026-5435

More information

Details

A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.

Severity

Moderate

References


glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

CVE-2026-5928

More information

Details

A flaw was found in glibc (GNU C Library). When the ungetwc function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.

Severity

Moderate

References


glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

CVE-2026-6238

More information

Details

A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.

Severity

Moderate

References


acl: Symlink traversal privilege escalation via libacl functions

CVE-2026-54369

More information

Details

A flaw was found in the acl package, specifically within its libacl pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.

Severity

Important

References


acl: TOCTOU Symlink Traversal via getfacl/setfacl

CVE-2026-54370

More information

Details

A time-of-check to time-of-use (TOCTOU) race condition vulnerability was found in acl. By replacing a pathname component with a symbolic link between a security check and subsequent file operations, an attacker can redirect file access control list operations. This occurs when privileged processes invoke getfacl or setfacl over an attacker-controlled path, potentially leading to local privilege escalation.

Severity

Important

References


libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling

CVE-2025-6170

More information

Details

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.

Severity

Low

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot requested review from a team and rhacs-bot as code owners July 22, 2026 14:41
@red-hat-konflux
red-hat-konflux Bot enabled auto-merge (squash) July 22, 2026 14:41

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@red-hat-konflux
red-hat-konflux Bot merged commit 36bb0d0 into master Jul 22, 2026
38 of 41 checks passed
@red-hat-konflux
red-hat-konflux Bot deleted the konflux/mintmaker/master/lock-file-maintenance-vulnerability branch July 22, 2026 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant