NO-ISSUE: Refresh RPM lockfiles [SECURITY]#703
NO-ISSUE: Refresh RPM lockfiles [SECURITY]#703red-hat-konflux[bot] wants to merge 1 commit intomainfrom
Conversation
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
|
@red-hat-konflux[bot]: This pull request explicitly references no jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is APPROVED Approval requirements bypassed by manually added approval. This pull-request has been approved by: red-hat-konflux[bot] The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
2 similar comments
|
[APPROVALNOTIFIER] This PR is APPROVED Approval requirements bypassed by manually added approval. This pull-request has been approved by: red-hat-konflux[bot] The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
[APPROVALNOTIFIER] This PR is APPROVED Approval requirements bypassed by manually added approval. This pull-request has been approved by: red-hat-konflux[bot] The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/retest |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #703 +/- ##
=======================================
Coverage 59.02% 59.02%
=======================================
Files 27 27
Lines 1674 1674
=======================================
Hits 988 988
Misses 524 524
Partials 162 162 🚀 New features to boost your workflow:
|
|
@red-hat-konflux[bot]: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
This PR contains the following updates:
File rpm-prefetching/rpms.in.yaml:
2.69-39.el9->2.69-41.el911.5.0-5.el9_5->11.5.0-11.el91:27.2-14.el9_6.2->1:27.2-18.el911.5.0-5.el9_5->11.5.0-11.el92.34-168.el9_6.23->2.34-231.el9_7.25.14.0-570.46.1.el9_6->5.14.0-611.34.1.el9_711.5.0-5.el9_5->11.5.0-11.el93.6-1.el9->3.6-3.el911.5.0-5.el9_5->11.5.0-11.el92.37.4-21.el9->2.37.4-21.el9_710.40-5.el9->10.40-6.el910.40-5.el9->10.40-6.el910.40-5.el9->10.40-6.el91.92-2.el9->1.94-3.el92.35.2-63.el9->2.35.2-67.el9_7.12.35.2-63.el9->2.35.2-67.el9_7.10.190-2.el9->0.193-1.el92.37.4-21.el9->2.37.4-21.el9_711.5.0-5.el9_5->11.5.0-11.el92.37.4-21.el9->2.37.4-21.el9_72.37.4-21.el9->2.37.4-21.el9_76.2-10.20210508.el9_6.2->6.2-12.20210508.el92.34-168.el9_6.23->2.34-231.el9_7.2util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames
CVE-2025-14104
More information
Details
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the
setpwnam()function, affecting SUID (Set User ID) login-utils utilities writing to the password database.Severity
Moderate
References
binutils: GNU Binutils Linker heap-based overflow
CVE-2025-11083
More information
Details
A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".
Severity
Moderate
References
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.