Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#1249

Merged
red-hat-konflux[bot] merged 1 commit into
release-0.2from
konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability
Jul 22, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#1249
red-hat-konflux[bot] merged 1 commit into
release-0.2from
konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
python3.12 3.12.13-2.el8_10 -> 3.12.13-3.el8_10
python3.12-libs 3.12.13-2.el8_10 -> 3.12.13-3.el8_10
acl 2.2.53-3.el8 -> 2.4.0-1.el8_10
glib2 2.56.4-169.el8_10 -> 2.56.4-170.el8_10
glibc 2.28-251.el8_10.38 -> 2.28-251.el8_10.40
glibc-all-langpacks 2.28-251.el8_10.38 -> 2.28-251.el8_10.40
glibc-common 2.28-251.el8_10.38 -> 2.28-251.el8_10.40
glibc-devel 2.28-251.el8_10.38 -> 2.28-251.el8_10.40
glibc-gconv-extra 2.28-251.el8_10.38 -> 2.28-251.el8_10.40
glibc-headers 2.28-251.el8_10.38 -> 2.28-251.el8_10.40
kernel-headers 4.18.0-553.139.1.el8_10 -> 4.18.0-553.146.1.el8_10
libacl 2.2.53-3.el8 -> 2.4.0-1.el8_10
libtasn1 4.13-5.el8_10 -> 4.13-6.el8_10
libxml2 2.9.7-21.el8_10.5 -> 2.9.7-21.el8_10.6
openssl 1:1.1.1k-16.el8_6 -> 1:1.1.1k-17.el8_6
openssl-devel 1:1.1.1k-16.el8_6 -> 1:1.1.1k-17.el8_6
openssl-libs 1:1.1.1k-16.el8_6 -> 1:1.1.1k-17.el8_6
platform-python 3.6.8-76.el8_10 -> 3.6.8-77.el8_10
python3-libs 3.6.8-76.el8_10 -> 3.6.8-77.el8_10

python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations

CVE-2026-15308

More information

Severity

Important

References


python: Python: Command-line option injection in webbrowser.open() via crafted URLs

CVE-2026-4519

More information

Severity

Important

References


python: Quadratic complexity in os.path.expandvars() with user-controlled template

CVE-2025-6075

More information

Severity

Important

References


cpython: Out-of-memory when loading Plist

CVE-2025-13837

More information

Severity

Important

References


cpython: Header injection via newlines in data URL mediatype in Python

CVE-2025-15282

More information

Severity

Important

References


firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing

CVE-2025-59375

More information

Severity

Important

References


cpython: Header injection in http.cookies.Morsel in Python

CVE-2026-0672

More information

Severity

Important

References


python: Python: HTTP header injection via CR/LF in proxy tunnel headers

CVE-2026-1502

More information

Severity

Important

References


cpython: CPython: Logging Bypass in Legacy .pyc File Handling

CVE-2026-2297

More information

Severity

Important

References


cpython: Incomplete control character validation in http.cookies

CVE-2026-3644

More information

Severity

Important

References


cpython: Stack overflow parsing XML with deeply nested DTD content models

CVE-2026-4224

More information

Severity

Important

References


python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API

CVE-2026-4786

More information

Severity

Important

References


python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules

CVE-2026-6100

More information

Severity

Important

References


acl: Symlink traversal privilege escalation via libacl functions

CVE-2026-54369

More information

Severity

Important

References


acl: TOCTOU Symlink Traversal via getfacl/setfacl

CVE-2026-54370

More information

Severity

Important

References


glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"

CVE-2026-58016

More information

Severity

Important

References


glibc: glibc: Out-of-bounds write via TSIG record processing

CVE-2026-5435

More information

Severity

Moderate

References


glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

CVE-2026-5928

More information

Severity

Moderate

References


glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

CVE-2026-6238

More information

Severity

Moderate

References


libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string

CVE-2025-13151

More information

Severity

Low

References


libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling

CVE-2025-6170

More information

Severity

Low

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux
red-hat-konflux Bot requested review from a team and rhacs-bot as code owners July 22, 2026 01:31
@red-hat-konflux
red-hat-konflux Bot enabled auto-merge (squash) July 22, 2026 01:31

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability branch 2 times, most recently from 1d60846 to c15c67e Compare July 22, 2026 15:05
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability branch from c15c67e to 99786d9 Compare July 22, 2026 19:52
@red-hat-konflux
red-hat-konflux Bot merged commit 55df1bc into release-0.2 Jul 22, 2026
23 checks passed
@red-hat-konflux
red-hat-konflux Bot deleted the konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability branch July 22, 2026 20:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant