Skip to content

chore(deps): refresh rpm lockfiles [SECURITY] - #3703

Open
red-hat-konflux[bot] wants to merge 1 commit into
release-3.25from
konflux/mintmaker/release-3.25/lock-file-maintenance-vulnerability
Open

chore(deps): refresh rpm lockfiles [SECURITY]#3703
red-hat-konflux[bot] wants to merge 1 commit into
release-3.25from
konflux/mintmaker/release-3.25/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
glibc-devel 2.34-274.el9_8 -> 2.34-275.el9_8
glibc 2.34-274.el9_8 -> 2.34-275.el9_8
glibc-common 2.34-274.el9_8 -> 2.34-275.el9_8
glibc-gconv-extra 2.34-274.el9_8 -> 2.34-275.el9_8
glibc-minimal-langpack 2.34-274.el9_8 -> 2.34-275.el9_8
p11-kit 0.26.2-1.el9 -> 0.26.4-1.el9_8
p11-kit-trust 0.26.2-1.el9 -> 0.26.4-1.el9_8
glibc-headers 2.34-274.el9_8 -> 2.34-275.el9_8

p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing

CVE-2026-13757

More information

Details

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

Severity

Moderate

References


p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters

CVE-2026-2100

More information

Details

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot requested review from a team and rhacs-bot as code owners August 3, 2026 15:17
@red-hat-konflux
red-hat-konflux Bot enabled auto-merge (squash) August 3, 2026 15:17

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant