chore(deps): refresh rpm lockfiles [SECURITY]#3459
Merged
red-hat-konflux[bot] merged 1 commit intoJul 22, 2026
Merged
Conversation
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
red-hat-konflux
Bot
deleted the
konflux/mintmaker/master/lock-file-maintenance-vulnerability
branch
July 22, 2026 15:12
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
File rpms.in.yaml:
2.34-272.el9_8->2.34-274.el9_82.34-272.el9_8->2.34-274.el9_82.34-272.el9_8->2.34-274.el9_82.34-272.el9_8->2.34-274.el9_82.3.1-4.el9->2.4.0-1.el9_82.9.13-14.el9_8.1->2.9.13-14.el9_8.21:3.5.5-4.el9_8->1:3.5.5-5.el9_81:3.5.5-4.el9_8->1:3.5.5-5.el9_8glibc: glibc: Out-of-bounds write via TSIG record processing
CVE-2026-5435
More information
Details
A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.
Severity
Moderate
References
glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings
CVE-2026-5928
More information
Details
A flaw was found in glibc (GNU C Library). When the
ungetwcfunction is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.Severity
Moderate
References
glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
CVE-2026-6238
More information
Details
A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.
Severity
Moderate
References
acl: Symlink traversal privilege escalation via libacl functions
CVE-2026-54369
More information
Details
A flaw was found in the
aclpackage, specifically within itslibaclpathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.Severity
Important
References
acl: TOCTOU Symlink Traversal via getfacl/setfacl
CVE-2026-54370
More information
Details
A time-of-check to time-of-use (TOCTOU) race condition vulnerability was found in
acl. By replacing a pathname component with a symbolic link between a security check and subsequent file operations, an attacker can redirect file access control list operations. This occurs when privileged processes invokegetfaclorsetfaclover an attacker-controlled path, potentially leading to local privilege escalation.Severity
Important
References
libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
CVE-2025-6170
More information
Details
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Severity
Low
References
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (in timezone Etc/UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.