Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#128

Open
konflux-internal-p02[bot] wants to merge 1 commit intorelease-8.1from
konflux/mintmaker/release-8.1/lock-file-maintenance-vulnerability
Open

chore(deps): refresh rpm lockfiles [SECURITY]#128
konflux-internal-p02[bot] wants to merge 1 commit intorelease-8.1from
konflux/mintmaker/release-8.1/lock-file-maintenance-vulnerability

Conversation

@konflux-internal-p02
Copy link
Contributor

@konflux-internal-p02 konflux-internal-p02 bot commented Feb 17, 2026

This PR contains the following updates:

File rpms.in.yaml:

Package Change
glibc 2.34-231.el9_7.2 -> 2.34-231.el9_7.10
glibc-common 2.34-231.el9_7.2 -> 2.34-231.el9_7.10
glibc-gconv-extra 2.34-231.el9_7.2 -> 2.34-231.el9_7.10
glibc-minimal-langpack 2.34-231.el9_7.2 -> 2.34-231.el9_7.10
tzdata 2025b-2.el9 -> 2025c-1.el9

glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

CVE-2025-15281

More information

Details

A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.

Severity

Moderate

References


glibc: Integer overflow in memalign leads to heap corruption

CVE-2026-0861

More information

Details

A flaw was found in the glibc library. Passing an excessively large alignment value to the memalign suite of functions, such as memalign, posix_memalign, aligned_alloc, valloc and pvalloc, an integer overflow can occur during internal size calculations due to improper overflow checks, causing an allocation of a small chunk of memory which is subsequently used for writing. This issue can result in an application crash or heap memory corruption.

Severity

Moderate

References


glibc: glibc: Information disclosure via zero-valued network query

CVE-2026-0915

More information

Details

A flaw was found in glibc, the GNU C Library. When an application calls the getnetbyaddr or getnetbyaddr_r functions to resolve a network address, and the system's nsswitch.conf file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: konflux-internal-p02 <170854209+konflux-internal-p02[bot]@users.noreply.github.com>
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 17, 2026
@konflux-internal-p02
Copy link
Contributor Author

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 17, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 18, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 19, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 20, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 20, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 28, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 28, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 28, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 28, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Feb 28, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Feb 28, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 1, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] - abandoned Mar 2, 2026
@konflux-internal-p02 konflux-internal-p02 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] - abandoned chore(deps): refresh rpm lockfiles [SECURITY] Mar 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants