Skip to content

chore(deps): refresh rpm lockfiles [SECURITY] - #271

Merged
red-hat-konflux-kflux-prd-rh02[bot] merged 1 commit into
release-0.2from
konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability
Oct 9, 2026
Merged

red-hat-konflux-kflux-prd-rh02[bot] merged 1 commit into
release-0.2from
konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux-kflux-prd-rh02

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
glibc 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-common 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-gconv-extra 2.34-275.el9_8 -> 2.34-283.el9_8
glibc-minimal-langpack 2.34-275.el9_8 -> 2.34-283.el9_8
openssl 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
openssl-libs 1:3.5.8-1.el9_8 -> 1:3.5.8-2.el9_8
tzdata 2026c-1.el9_8 -> 2026e-1.el9_8

glibc: glibc: Process abort due to invalid memory in wordexp

CVE-2026-6368

More information

Details

A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS).

Severity

Moderate

References


glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion

CVE-2026-6791

More information

Details

A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the wordexp function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application.

Severity

Moderate

References


glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string

CVE-2026-18374

More information

Details

A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the fopen function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information.

Severity

Moderate

References


glibc: Fix out-of-bounds array write in tdelete

CVE-2026-19542

More information

Details

A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the tdelete function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information.

Severity

Moderate

References


glibc: Non-progress DoS in SHIFT_JISX0213 -&gt

CVE-2026-77117

More information

Details

A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text.

Severity

Moderate

References


glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state

CVE-2026-80489

More information

Details

A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

E2E Test Results

Commit: 8c21b9e
Workflow Run: View Details
Artifacts: Download test results & logs

=== Evaluation Summary ===

  ✓ list-clusters (assertions: 3/3)
  ✓ rhsa-not-supported (assertions: 2/2)
  ✓ cve-cluster-does-exist (assertions: 3/3)
  ✓ cve-cluster-list (assertions: 3/3)
  ✓ cve-cluster-does-not-exist (assertions: 3/3)
  ✓ cve-clusters-general (assertions: 3/3)
  ✓ cve-log4shell (assertions: 3/3)
  ✓ cve-multiple (assertions: 3/3)
  ✓ cve-detected-workloads (assertions: 3/3)
  ✓ cve-detected-clusters (assertions: 3/3)
  ~ cve-nonexistent (assertions: 2/3)
      - MaxToolCalls: Too many tool calls: expected <= 5, got 8

Tasks:      11/11 passed (100.00%)
Assertions: 31/32 passed (96.88%)
Tokens:     ~59018 (estimate - excludes system prompt & cache)
MCP schemas: ~12562 (included in token total)
Agent used tokens:
  Input:  13219 tokens
  Output: 24039 tokens
Judge used tokens:
  Input:  52252 tokens
  Output: 49655 tokens

@codecov-commenter

codecov-commenter commented Oct 9, 2026 •

Copy link
Copy Markdown

❌ 2 Tests Failed:

Tests completed Failed Passed Skipped
380 2 378 12
View the full list of 2 ❄️ flaky test(s)
::policy 1

Flake rate in main: 100.00% (Passed 0 times, Failed 176 times)

Stack Traces | 0s run time
- test violation 1
- test violation 2
- test violation 3
::policy 4

Flake rate in main: 100.00% (Passed 0 times, Failed 176 times)

Stack Traces | 0s run time
- testing multiple alert violation messages 1
- testing multiple alert violation messages 2
- testing multiple alert violation messages 3

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@mtodor
mtodor force-pushed the konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability branch from 8fb3e19 to aff4928 Compare October 9, 2026 12:04
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability branch from aff4928 to 8c21b9e Compare October 9, 2026 12:06
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot merged commit f7617e5 into release-0.2 Oct 9, 2026
11 checks passed
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot deleted the konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability branch October 9, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants