Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#65

Open
konflux-internal-p02[bot] wants to merge 1 commit intorelease-9.0from
konflux/mintmaker/release-9.0/lock-file-maintenance-vulnerability
Open

chore(deps): refresh rpm lockfiles [SECURITY]#65
konflux-internal-p02[bot] wants to merge 1 commit intorelease-9.0from
konflux/mintmaker/release-9.0/lock-file-maintenance-vulnerability

Conversation

@konflux-internal-p02
Copy link
Contributor

@konflux-internal-p02 konflux-internal-p02 bot commented Dec 1, 2025

This PR contains the following updates:

File rpms.in.yaml:

Package Change
libblkid 2.37.4-21.el9 -> 2.37.4-21.el9_7
libfdisk 2.37.4-21.el9 -> 2.37.4-21.el9_7
libmount 2.37.4-21.el9 -> 2.37.4-21.el9_7
libsmartcols 2.37.4-21.el9 -> 2.37.4-21.el9_7
libuuid 2.37.4-21.el9 -> 2.37.4-21.el9_7
util-linux 2.37.4-21.el9 -> 2.37.4-21.el9_7
util-linux-core 2.37.4-21.el9 -> 2.37.4-21.el9_7

util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames

CVE-2025-14104

More information

Details

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@konflux-internal-p02 konflux-internal-p02 bot force-pushed the konflux/mintmaker/release-9.0/lock-file-maintenance-vulnerability branch from 49a2c85 to b36e32c Compare December 17, 2025 20:11
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the konflux/mintmaker/release-9.0/lock-file-maintenance-vulnerability branch from b36e32c to 0c6d549 Compare January 12, 2026 04:11
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the konflux/mintmaker/release-9.0/lock-file-maintenance-vulnerability branch from 0c6d549 to 24257f8 Compare February 5, 2026 00:19
Signed-off-by: konflux-internal-p02 <170854209+konflux-internal-p02[bot]@users.noreply.github.com>
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the konflux/mintmaker/release-9.0/lock-file-maintenance-vulnerability branch from 24257f8 to ef9dd67 Compare February 6, 2026 12:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants