Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#2025

Merged
jeff-roche merged 2 commits intorelease-4.16from
konflux/mintmaker/release-4.16/lock-file-maintenance-vulnerability
Feb 20, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#2025
jeff-roche merged 2 commits intorelease-4.16from
konflux/mintmaker/release-4.16/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux
Copy link
Copy Markdown
Contributor

@red-hat-konflux red-hat-konflux Bot commented Feb 5, 2026

This PR contains the following updates:

File release/operator/rpms.in.yaml:

Package Change
libblkid 2.37.4-21.el9 -> 2.37.4-21.el9_7
libfdisk 2.37.4-21.el9 -> 2.37.4-21.el9_7
libmount 2.37.4-21.el9 -> 2.37.4-21.el9_7
libsmartcols 2.37.4-21.el9 -> 2.37.4-21.el9_7
libuuid 2.37.4-21.el9 -> 2.37.4-21.el9_7
openssl 1:3.5.1-5.el9_7 -> 1:3.5.1-7.el9_7
openssl-libs 1:3.5.1-5.el9_7 -> 1:3.5.1-7.el9_7
util-linux 2.37.4-21.el9 -> 2.37.4-21.el9_7
util-linux-core 2.37.4-21.el9 -> 2.37.4-21.el9_7

util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames

CVE-2025-14104

More information

Details

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@openshift-ci openshift-ci Bot added the size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. label Feb 5, 2026
@openshift-ci openshift-ci Bot requested review from eggfoobar and qJkee February 5, 2026 00:58
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Feb 5, 2026

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: red-hat-konflux[bot]
Once this PR has been reviewed and has the lgtm label, please assign qjkee for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Feb 20, 2026
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Feb 20, 2026

@red-hat-konflux[bot]: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@jeff-roche jeff-roche merged commit 2a87528 into release-4.16 Feb 20, 2026
5 of 7 checks passed
@jeff-roche jeff-roche deleted the konflux/mintmaker/release-4.16/lock-file-maintenance-vulnerability branch February 20, 2026 15:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant