chore(deps): refresh rpm lockfiles [SECURITY] - #3714
Conversation
|
@github-actions[bot]: The Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
a33fd6e to
f32f70e
Compare
|
@red-hat-konflux[bot]: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
This PR contains the following updates:
File rpms.in.yaml:
1.12-1.el9->1.12-2.el9_82.9.13-14.el9_8.2->2.9.13-14.el9_8.42:1.34-11.el9->2:1.34-13.el9_8gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility
CVE-2026-41991
More information
Details
A flaw was found in the
gzexeutility of GNUgzip. When themktemputility is not available,gzexecreates temporary files with predictable names based on the process ID. A local attacker can exploit this by pre-creating a symbolic link to an arbitrary file at the predicted temporary file path. This can lead to a Time-of-Check to Time-of-Use (TOCTOU) condition, allowing the attacker to overwrite arbitrary files on the system.Severity
Moderate
References
gzip: gzip: Information disclosure via global buffer overflow in LZH decompression
CVE-2026-41992
More information
Details
A flaw was found in GNU gzip. This global buffer overflow vulnerability in the LZH decompression logic is caused by improper reuse of shared global state between different decompression formats. An attacker can exploit this by providing a specially crafted LZW file followed by a specially crafted LZH file to the
gzip -dcommand. This can lead to an out-of-bounds read, potentially resulting in information disclosure.Severity
Moderate
References
libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
CVE-2026-6653
More information
Details
A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the
xmlParseInternalSubsetfunction by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable.Severity
Moderate
References
libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow
CVE-2026-11979
More information
Details
A flaw was found in libxml2, specifically within the xmlcatalog utility when operating in shell mode. An attacker can exploit multiple stack-based buffer overflows by providing an excessively long input line. This leads to memory corruption, which may cause the application to crash or potentially allow the attacker to execute arbitrary code within the context of the xmlcatalog process.
Severity
Moderate
References
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (in timezone Etc/UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.