Skip to content

chore(deps): refresh rpm lockfiles (main) [SECURITY]#198

Merged
svghadi merged 1 commit into
mainfrom
konflux/mintmaker/main-main/lock-file-maintenance-vulnerability
Sep 15, 2025
Merged

chore(deps): refresh rpm lockfiles (main) [SECURITY]#198
svghadi merged 1 commit into
mainfrom
konflux/mintmaker/main-main/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux
Copy link
Copy Markdown
Contributor

@red-hat-konflux red-hat-konflux Bot commented Sep 10, 2025

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

cpython: Cpython infinite loop when parsing a tarfile

CVE-2025-8194

More information

Details

A flaw was found in the Python tarfile module. Processing a specially crafted tar archive, specifically an archive with negative offsets, can cause an infinite loop and deadlock. This issue results in a denial of service in the Python application using the tarfile module.

Severity

Moderate

References


linux-pam: Incomplete fix for CVE-2025-6020

CVE-2025-8941

More information

Details

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Severity

Important

References


linux-pam: Linux-pam directory Traversal

CVE-2025-6020

More information

Details

A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.

Severity

Important

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.

This PR has been generated by MintMaker (powered by Renovate Bot).

@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/lock-file-maintenance-vulnerability branch 21 times, most recently from 718c515 to 615f4e5 Compare September 11, 2025 20:32
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/lock-file-maintenance-vulnerability branch from 615f4e5 to 40b4d5a Compare September 11, 2025 20:33
@svghadi svghadi merged commit 592ebf8 into main Sep 15, 2025
15 of 16 checks passed
@svghadi svghadi deleted the konflux/mintmaker/main-main/lock-file-maintenance-vulnerability branch September 18, 2025 03:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant