Repository navigation
chore(deps): refresh rpm lockfiles [SECURITY] - #91
Open
red-hat-konflux[bot] wants to merge 1 commit into
Open
red-hat-konflux[bot] wants to merge 1 commit into
red-hat-konflux[bot] wants to merge 1 commit into
Conversation
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/main/lock-file-maintenance-vulnerability
branch
2 times, most recently
from
October 10, 2026 02:43
36507bc to
14b536e
Compare
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/main/lock-file-maintenance-vulnerability
branch
from
October 10, 2026 07:19
14b536e to
18fc44f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
File deploy/konflux/cli/rpms.in.yaml:
2.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_81:3.5.8-1.el9_8->1:3.5.8-2.el9_81:3.5.8-1.el9_8->1:3.5.8-2.el9_82026c-1.el9_8->2026e-1.el9_8File deploy/konflux/e2e-odh/rpms.in.yaml:
2.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_81:3.5.8-1.el9_8->1:3.5.8-2.el9_81:3.5.8-1.el9_8->1:3.5.8-2.el9_82026c-1.el9_8->2026e-1.el9_8File deploy/konflux/gateway/rpms.in.yaml:
2.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_81:3.5.8-1.el9_8->1:3.5.8-2.el9_82026c-1.el9_8->2026e-1.el9_8File deploy/konflux/openclaw/rpms.in.yaml:
2.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_81:3.5.8-1.el9_8->1:3.5.8-2.el9_82026c-1.el9_8->2026e-1.el9_8File deploy/konflux/sandbox/rpms.in.yaml:
2.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_85.14.0-687.54.1.el9_8->5.14.0-687.56.1.el9_82026c-1.el9_8->2026e-1.el9_8File deploy/konflux/supervisor/rpms.in.yaml:
2.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_82.34-275.el9_8->2.34-283.el9_81:3.5.8-1.el9_8->1:3.5.8-2.el9_82026c-1.el9_8->2026e-1.el9_8glibc: glibc: Process abort due to invalid memory in wordexp
CVE-2026-6368
More information
Severity
Moderate
References
glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion
CVE-2026-6791
More information
Severity
Moderate
References
glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string
CVE-2026-18374
More information
Severity
Moderate
References
glibc: Fix out-of-bounds array write in tdelete
CVE-2026-19542
More information
Severity
Moderate
References
glibc: Non-progress DoS in SHIFT_JISX0213 ->
CVE-2026-77117
More information
Severity
Moderate
References
glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state
CVE-2026-80489
More information
Severity
Moderate
References
glibc: glibc: Process abort due to invalid memory in wordexp
CVE-2026-6368
More information
Details
A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS).
Severity
Moderate
References
glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion
CVE-2026-6791
More information
Details
A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the
wordexpfunction can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application.Severity
Moderate
References
glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string
CVE-2026-18374
More information
Details
A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the
fopenfunction handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information.Severity
Moderate
References
glibc: Fix out-of-bounds array write in tdelete
CVE-2026-19542
More information
Details
A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the
tdeletefunction. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information.Severity
Moderate
References
glibc: Non-progress DoS in SHIFT_JISX0213 ->
CVE-2026-77117
More information
Details
A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text.
Severity
Moderate
References
glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state
CVE-2026-80489
More information
Details
A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input.
Severity
Moderate
References
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.