Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#3135

Merged
red-hat-konflux[bot] merged 1 commit intorelease-3.24from
konflux/mintmaker/release-3.24/lock-file-maintenance-vulnerability
Mar 23, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#3135
red-hat-konflux[bot] merged 1 commit intorelease-3.24from
konflux/mintmaker/release-3.24/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux
Copy link
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
glibc 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-all-langpacks 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-common 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-devel 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-gconv-extra 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-headers 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
tzdata 2025c-1.el8 -> 2026a-1.el8

glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

CVE-2025-15281

More information

Details

A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.

Severity

Moderate

References


glibc: glibc: Information disclosure via zero-valued network query

CVE-2026-0915

More information

Details

A flaw was found in glibc, the GNU C Library. When an application calls the getnetbyaddr or getnetbyaddr_r functions to resolve a network address, and the system's nsswitch.conf file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot requested review from a team and rhacs-bot as code owners March 23, 2026 17:54
@red-hat-konflux red-hat-konflux bot enabled auto-merge (squash) March 23, 2026 17:54
Copy link
Contributor

@rhacs-bot rhacs-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@codecov-commenter
Copy link

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 27.38%. Comparing base (8b03940) to head (379900d).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@              Coverage Diff              @@
##           release-3.24    #3135   +/-   ##
=============================================
  Coverage         27.38%   27.38%           
=============================================
  Files                95       95           
  Lines              5427     5427           
  Branches           2548     2548           
=============================================
  Hits               1486     1486           
  Misses             3214     3214           
  Partials            727      727           
Flag Coverage Δ
collector-unit-tests 27.38% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@red-hat-konflux red-hat-konflux bot merged commit 6667023 into release-3.24 Mar 23, 2026
85 of 91 checks passed
@red-hat-konflux red-hat-konflux bot deleted the konflux/mintmaker/release-3.24/lock-file-maintenance-vulnerability branch March 23, 2026 19:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants