Skip to content

chore(deps): refresh rpm lockfiles (main) [SECURITY]#262

Merged
svghadi merged 1 commit into
mainfrom
konflux/mintmaker/main-main/lock-file-maintenance-vulnerability
Sep 28, 2025
Merged

chore(deps): refresh rpm lockfiles (main) [SECURITY]#262
svghadi merged 1 commit into
mainfrom
konflux/mintmaker/main-main/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux
Copy link
Copy Markdown
Contributor

@red-hat-konflux red-hat-konflux Bot commented Sep 26, 2025

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled

CVE-2025-26465

More information

Details

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.

This PR has been generated by MintMaker (powered by Renovate Bot).

@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/lock-file-maintenance-vulnerability branch 3 times, most recently from 23a38d6 to 4e4b5d5 Compare September 26, 2025 08:41
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/main-main/lock-file-maintenance-vulnerability branch from 4e4b5d5 to 459990d Compare September 26, 2025 08:41
@svghadi svghadi merged commit bbe869d into main Sep 28, 2025
0 of 16 checks passed
@svghadi svghadi deleted the konflux/mintmaker/main-main/lock-file-maintenance-vulnerability branch September 28, 2025 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant