chore(deps): refresh rpm lockfiles [SECURITY] - #3887
Merged
red-hat-konflux[bot] merged 1 commit intoSep 1, 2026
Merged
Conversation
rhacs-bot
approved these changes
Aug 27, 2026
rhacs-bot
left a comment
Contributor
There was a problem hiding this comment.
Auto-approved by automation.
rhacs-bot
approved these changes
Aug 27, 2026
rhacs-bot
left a comment
Contributor
There was a problem hiding this comment.
Auto-approved by automation.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release-3.25 #3887 +/- ##
=============================================
Coverage 27.34% 27.34%
=============================================
Files 95 95
Lines 5420 5420
Branches 2545 2545
=============================================
Hits 1482 1482
Misses 3211 3211
Partials 727 727
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/release-3.25/lock-file-maintenance-vulnerability
branch
from
August 28, 2026 02:56
72581b0 to
606b5d6
Compare
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/release-3.25/lock-file-maintenance-vulnerability
branch
from
September 1, 2026 02:18
606b5d6 to
e4ef7f9
Compare
red-hat-konflux
Bot
deleted the
konflux/mintmaker/release-3.25/lock-file-maintenance-vulnerability
branch
September 1, 2026 04:29
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
File rpms.in.yaml:
28-7.el9->28-9.el9_81.12-1.el9->1.12-2.el9_82.9.13-14.el9_8.2->2.9.13-14.el9_8.42:1.34-11.el9->2:1.34-13.el9_8dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup
CVE-2026-16730
More information
Details
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
Severity
Moderate
References
gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility
CVE-2026-41991
More information
Details
A flaw was found in the
gzexeutility of GNUgzip. When themktemputility is not available,gzexecreates temporary files with predictable names based on the process ID. A local attacker can exploit this by pre-creating a symbolic link to an arbitrary file at the predicted temporary file path. This can lead to a Time-of-Check to Time-of-Use (TOCTOU) condition, allowing the attacker to overwrite arbitrary files on the system.Severity
Moderate
References
gzip: gzip: Information disclosure via global buffer overflow in LZH decompression
CVE-2026-41992
More information
Details
A flaw was found in GNU gzip. This global buffer overflow vulnerability in the LZH decompression logic is caused by improper reuse of shared global state between different decompression formats. An attacker can exploit this by providing a specially crafted LZW file followed by a specially crafted LZH file to the
gzip -dcommand. This can lead to an out-of-bounds read, potentially resulting in information disclosure.Severity
Moderate
References
libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
CVE-2026-6653
More information
Details
A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the
xmlParseInternalSubsetfunction by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable.Severity
Moderate
References
libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow
CVE-2026-11979
More information
Details
A flaw was found in libxml2, specifically within the xmlcatalog utility when operating in shell mode. An attacker can exploit multiple stack-based buffer overflows by providing an excessively long input line. This leads to memory corruption, which may cause the application to crash or potentially allow the attacker to execute arbitrary code within the context of the xmlcatalog process.
Severity
Moderate
References
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (in timezone Etc/UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.