Skip to content

chore(deps): refresh rpm lockfiles [SECURITY] - #91

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/lock-file-maintenance-vulnerability
Open

red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

This PR contains the following updates:

File deploy/konflux/cli/rpms.in.yaml:

Package Change
glibc 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-common 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-gconv-extra 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-minimal-langpack 2.34-275.el9_8 -> 2.34-283.el9_8
openssl 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
openssl-libs 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
tzdata 2026c-1.el9_8 -> 2026e-1.el9_8

File deploy/konflux/e2e-odh/rpms.in.yaml:

Package Change
glibc 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-common 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-minimal-langpack 2.34-275.el9_8 -> 2.34-283.el9_8
openssl 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
openssl-libs 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
tzdata 2026c-1.el9_8 -> 2026e-1.el9_8

File deploy/konflux/gateway/rpms.in.yaml:

Package Change
glibc 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-common 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-minimal-langpack 2.34-275.el9_8 -> 2.34-283.el9_8
openssl-libs 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
tzdata 2026c-1.el9_8 -> 2026e-1.el9_8

File deploy/konflux/openclaw/rpms.in.yaml:

Package Change
glibc 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-common 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-minimal-langpack 2.34-275.el9_8 -> 2.34-283.el9_8
openssl-libs 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
tzdata 2026c-1.el9_8 -> 2026e-1.el9_8

File deploy/konflux/sandbox/rpms.in.yaml:

Package Change
glibc-devel 2.34-275.el9_8 -> 2.34-283.el9_8
glibc 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-common 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-minimal-langpack 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-static 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-headers 2.34-275.el9_8 -> 2.34-283.el9_8
kernel-headers 5.14.0-687.54.1.el9_8 -> 5.14.0-687.56.1.el9_8
tzdata 2026c-1.el9_8 -> 2026e-1.el9_8

File deploy/konflux/supervisor/rpms.in.yaml:

Package Change
glibc 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-common 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-minimal-langpack 2.34-275.el9_8 -> 2.34-283.el9_8
openssl-libs 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
tzdata 2026c-1.el9_8 -> 2026e-1.el9_8

glibc: glibc: Process abort due to invalid memory in wordexp

CVE-2026-6368

More information

Severity

Moderate

References


glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion

CVE-2026-6791

More information

Severity

Moderate

References


glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string

CVE-2026-18374

More information

Severity

Moderate

References


glibc: Fix out-of-bounds array write in tdelete

CVE-2026-19542

More information

Severity

Moderate

References


glibc: Non-progress DoS in SHIFT_JISX0213 -&gt

CVE-2026-77117

More information

Severity

Moderate

References


glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state

CVE-2026-80489

More information

Severity

Moderate

References


glibc: glibc: Process abort due to invalid memory in wordexp

CVE-2026-6368

More information

Details

A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS).

Severity

Moderate

References


glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion

CVE-2026-6791

More information

Details

A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the wordexp function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application.

Severity

Moderate

References


glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string

CVE-2026-18374

More information

Details

A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the fopen function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information.

Severity

Moderate

References


glibc: Fix out-of-bounds array write in tdelete

CVE-2026-19542

More information

Details

A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the tdelete function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information.

Severity

Moderate

References


glibc: Non-progress DoS in SHIFT_JISX0213 -&gt

CVE-2026-77117

More information

Details

A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text.

Severity

Moderate

References


glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state

CVE-2026-80489

More information

Details

A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux
red-hat-konflux Bot enabled auto-merge (squash) October 9, 2026 01:00
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Central YAML (base), Organization UI (inherited)
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 073689c1-03cf-4673-844a-be99a3bd6cba




📥 Commits

Reviewing files that changed from the base of the PR and between 4f48833 and f464ec8.





📒 Files selected for processing (6)
  • deploy/konflux/cli/rpms.lock.yaml
  • deploy/konflux/e2e-odh/rpms.lock.yaml
  • deploy/konflux/gateway/rpms.lock.yaml
  • deploy/konflux/openclaw/rpms.lock.yaml
  • deploy/konflux/sandbox/rpms.lock.yaml
  • deploy/konflux/supervisor/rpms.lock.yaml




Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.






📝 Walkthrough
📝 Walkthrough
📝 Walkthrough
📝 Walkthrough

Walkthrough

The six Konflux RPM lockfiles update package versions and related artifact metadata. The updates include glibc-family packages across both architectures, plus selected OpenSSL, tzdata, kernel-header, and glibc development packages.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes









Merge Risk: ⚪ Minimal · up to f464e

This PR refreshes pinned RPM records across the six Konflux targets; no concrete build or runtime regression is established in the supplied evidence. It appears ready to merge subject to normal validation.

🚥 Pre-merge checks | ✅ 10
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly identifies a dependency lockfile refresh and correctly indicates the security-update intent. It matches the primary changes across all six RPM lockfiles.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Contribution Quality And Spam Detection Passed The diff updates six RPM lockfiles with matching package URLs, EVRs, source RPMs, sizes, and SHA-256 checksums. It adds no application code or validation logic. The description uses a formulaic depend…
No Hardcoded Secrets Passed PASS. The pull request changes only six RPM lockfiles. Added URLs point to public cdn-ubi.redhat.com paths and contain no embedded credentials. No added API-key, secret, token, password, private-key…
No Weak Cryptography Passed PASS. The PR changes only six RPM lockfiles. The diff updates package URLs, versions, sizes, source RPMs, and SHA-256 checksums. It introduces no MD5, SHA-1, DES, RC4, 3DES, Blowfish, ECB, custom cryp…
No Injection Vectors Passed The PR changes only six rpms.lock.yaml files. The diff updates static RPM URLs, sizes, SHA-256 checksums, EVRs, and source RPM names. No SQL construction, shell=True, os.system, eval/exec, u…
No Privileged Containers Passed PASS — The authoritative pull-request diff changes only six RPM lockfiles under deploy/konflux/. The diff contains package versions, URLs, sizes, checksums, and source RPM metadata only. It adds no …
No Sensitive Data In Logs Passed The pull request changes only six RPM lockfiles. The added lines update package URLs, versions, sizes, checksums, and source RPM metadata. No logging statements or sensitive-data fields appear in the …









Comment @coderabbitai help to get the list of available commands.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch 2 times, most recently from 36507bc to 14b536e Compare October 10, 2026 02:43
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from 14b536e to 18fc44f Compare October 10, 2026 07:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants