Skip to content

chore(deps): refresh rpm lockfiles [SECURITY] - #196

Merged
red-hat-konflux-kflux-prd-rh02[bot] merged 1 commit into
release-0.2from
konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability
Aug 4, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#196
red-hat-konflux-kflux-prd-rh02[bot] merged 1 commit into
release-0.2from
konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux-kflux-prd-rh02

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
glibc 2.34-274.el9_8 -> 2.34-275.el9_8
glibc-common 2.34-274.el9_8 -> 2.34-275.el9_8
glibc-gconv-extra 2.34-274.el9_8 -> 2.34-275.el9_8
glibc-minimal-langpack 2.34-274.el9_8 -> 2.34-275.el9_8
p11-kit 0.26.2-1.el9 -> 0.26.4-1.el9_8
p11-kit-trust 0.26.2-1.el9 -> 0.26.4-1.el9_8

p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing

CVE-2026-13757

More information

Details

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

Severity

Moderate

References


p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters

CVE-2026-2100

More information

Details

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

E2E Test Results

Commit: ef9b2e4
Workflow Run: View Details
Artifacts: Download test results & logs

=== Evaluation Summary ===

  ✓ cve-clusters-general (assertions: 3/3)
  ✓ cve-cluster-does-not-exist (assertions: 3/3)
  ✓ cve-cluster-does-exist (assertions: 3/3)
  ✓ cve-detected-workloads (assertions: 3/3)
  ✓ cve-log4shell (assertions: 3/3)
  ✓ rhsa-not-supported (assertions: 2/2)
  ✓ cve-cluster-list (assertions: 3/3)
  ~ cve-nonexistent (assertions: 2/3)
      - MaxToolCalls: Too many tool calls: expected <= 5, got 7
  ✓ list-clusters (assertions: 3/3)
  ✗ cve-multiple (assertions: 3/3)
      one or more verification steps failed
  ✓ cve-detected-clusters (assertions: 3/3)

Tasks:      10/11 passed (90.91%)
Assertions: 31/32 passed (96.88%)
Tokens:     ~53845 (estimate - excludes system prompt & cache)
MCP schemas: ~12562 (included in token total)
Agent used tokens:
  Input:  12559 tokens
  Output: 20806 tokens
Judge used tokens:
  Input:  34305 tokens
  Output: 33189 tokens

Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability branch from 4890af9 to ef9b2e4 Compare August 4, 2026 12:04
@codecov-commenter

codecov-commenter commented Aug 4, 2026

Copy link
Copy Markdown

❌ 2 Tests Failed:

Tests completed Failed Passed Skipped
380 2 378 12
View the full list of 2 ❄️ flaky test(s)
::policy 1

Flake rate in main: 100.00% (Passed 0 times, Failed 100 times)

Stack Traces | 0s run time
- test violation 1
- test violation 2
- test violation 3
::policy 4

Flake rate in main: 100.00% (Passed 0 times, Failed 100 times)

Stack Traces | 0s run time
- testing multiple alert violation messages 1
- testing multiple alert violation messages 2
- testing multiple alert violation messages 3

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot merged commit c2c8c39 into release-0.2 Aug 4, 2026
11 checks passed
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot deleted the konflux/mintmaker/release-0.2/lock-file-maintenance-vulnerability branch August 4, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants