Skip to content

chore(deps): refresh rpm lockfiles [SECURITY] - #1632

Merged
red-hat-konflux[bot] merged 1 commit into
release-0.3from
konflux/mintmaker/release-0.3/lock-file-maintenance-vulnerability
Sep 2, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#1632
red-hat-konflux[bot] merged 1 commit into
release-0.3from
konflux/mintmaker/release-0.3/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
libssh 0.10.4-18.el9 -> 0.10.4-19.el9_8
libssh-config 0.10.4-18.el9 -> 0.10.4-19.el9_8

libssh: libssh: denial of service via zero advertised channel packet size

CVE-2026-59843

More information

Details

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

Severity

Moderate

References


libssh: libssh: denial of service via oversized SFTP read length

CVE-2026-59844

More information

Details

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

Severity

Moderate

References


libssh: libssh: denial of service via unchecked ProxyCommand fork() failure

CVE-2026-59845

More information

Details

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

Severity

Moderate

References


libssh: libssh: information disclosure via ProxyCommand %r username expansion

CVE-2026-59846

More information

Details

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

Severity

Moderate

References


libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification

CVE-2026-59847

More information

Details

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

Severity

Moderate

References


libssh: libssh: denial of service via SFTP responses with unknown request IDs

CVE-2026-59848

More information

Details

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.

Severity

Moderate

References


libssh: libssh: use-after-free via data callbacks on closed channels

CVE-2026-59850

More information

Details

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot requested review from a team and rhacs-bot as code owners September 2, 2026 03:59
@red-hat-konflux
red-hat-konflux Bot enabled auto-merge (squash) September 2, 2026 03:59

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@red-hat-konflux
red-hat-konflux Bot merged commit 1a2cc8f into release-0.3 Sep 2, 2026
27 checks passed
@red-hat-konflux
red-hat-konflux Bot deleted the konflux/mintmaker/release-0.3/lock-file-maintenance-vulnerability branch September 2, 2026 04:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant