Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#418

Open
red-hat-konflux[bot] wants to merge 1 commit intorelease-0.2from
konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability
Open

chore(deps): refresh rpm lockfiles [SECURITY]#418
red-hat-konflux[bot] wants to merge 1 commit intorelease-0.2from
konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux
Copy link
Contributor

@red-hat-konflux red-hat-konflux bot commented Mar 23, 2026

This PR contains the following updates:

File rpms.in.yaml:

Package Change
glibc 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-all-langpacks 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-common 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-devel 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-gconv-extra 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
glibc-headers 2.28-251.el8_10.27 -> 2.28-251.el8_10.31
grub2-common 1:2.02-169.el8_10 -> 1:2.02-170.el8_10.1
grub2-tools 1:2.02-169.el8_10 -> 1:2.02-170.el8_10.1
grub2-tools-minimal 1:2.02-169.el8_10 -> 1:2.02-170.el8_10.1
tzdata 2025c-1.el8 -> 2026a-1.el8

glibc: glibc: Information disclosure via zero-valued network query

CVE-2026-0915

More information

Details

A flaw was found in glibc, the GNU C Library. When an application calls the getnetbyaddr or getnetbyaddr_r functions to resolve a network address, and the system's nsswitch.conf file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system.

Severity

Moderate

References


glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

CVE-2025-15281

More information

Details

A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot requested review from a team and rhacs-bot as code owners March 23, 2026 17:52
@red-hat-konflux red-hat-konflux bot enabled auto-merge (squash) March 23, 2026 17:52
Copy link

@rhacs-bot rhacs-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

Copy link

@rhacs-bot rhacs-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant