Skip to content

chore(deps): rpm updates [security] #34

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: release-5.3
Choose a base branch
from

Conversation

konflux-internal-p02[bot]
Copy link

@konflux-internal-p02 konflux-internal-p02 bot commented Jul 29, 2025

This PR contains the following updates:

Package Update Change
glibc patch 2.28-251.el8_10.22 -> 2.28-251.el8_10.25
glibc-all-langpacks patch 2.28-251.el8_10.22 -> 2.28-251.el8_10.25
glibc-common patch 2.28-251.el8_10.22 -> 2.28-251.el8_10.25
glibc-gconv-extra patch 2.28-251.el8_10.22 -> 2.28-251.el8_10.25
libxml2 patch 2.9.7-21.el8_10.1 -> 2.9.7-21.el8_10.2
sqlite-libs patch 3.26.0-19.el8_9 -> 3.26.0-20.el8_10

glibc: Double free in glibc

CVE-2025-8058

More information

Severity

Moderate

References


glibc: buffer overflow in the GNU C Library's assert()

CVE-2025-0395

More information

Severity

Moderate

References


glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH

CVE-2025-4802

More information

Severity

Moderate

References


glibc: Vector register overwrite bug in glibc

CVE-2025-5702

More information

Severity

Moderate

References


libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr

CVE-2025-7425

More information

Severity

Important

References


libxml: Type confusion leads to Denial of service (DoS)

CVE-2025-49796

More information

Severity

Important

References


libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2

CVE-2025-6021

More information

Severity

Important

References


libxml: Heap use after free (UAF) leads to Denial of service (DoS)

CVE-2025-49794

More information

Severity

Important

References


libxml2: XXE vulnerability

CVE-2024-40896

More information

Severity

Critical

References


libxml: Null pointer dereference leads to Denial of service (DoS)

CVE-2025-49795

More information

Severity

Important

References


sqlite: Integer Truncation in SQLite

CVE-2025-6965

More information

Severity

Important

References


SQLite: integer overflow in SQLite

CVE-2025-3277

More information

Severity

Important

References


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.

This PR has been generated by MintMaker (powered by Renovate Bot).

@konflux-internal-p02 konflux-internal-p02 bot force-pushed the konflux/mintmaker/release-5.3/rpm-updates branch 2 times, most recently from 2c4e81f to 33ce8bb Compare August 4, 2025 05:15
Signed-off-by: konflux-internal-p02 <170854209+konflux-internal-p02[bot]@users.noreply.github.com>
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the konflux/mintmaker/release-5.3/rpm-updates branch from 33ce8bb to f1be8c9 Compare August 5, 2025 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants