Skip to content

chore(deps): refresh rpm lockfiles [SECURITY] - #1559

Merged
red-hat-konflux[bot] merged 1 commit into
release-0.3from
konflux/mintmaker/release-0.3/lock-file-maintenance-vulnerability
Aug 27, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#1559
red-hat-konflux[bot] merged 1 commit into
release-0.3from
konflux/mintmaker/release-0.3/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
kernel-headers 5.14.0-687.41.1.el9_8 -> 5.14.0-687.42.1.el9_8
libattr 2.5.1-3.el9 -> 2.6.0-1.el9_8

attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr

CVE-2026-54371

More information

Details

A flaw was found in the attr package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by getfattr or during backup restoration by setfattr, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux
red-hat-konflux Bot requested review from a team and rhacs-bot as code owners August 25, 2026 02:39
@red-hat-konflux
red-hat-konflux Bot enabled auto-merge (squash) August 25, 2026 02:39

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@rhacs-bot rhacs-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-0.3/lock-file-maintenance-vulnerability branch from 38d4043 to b1a4fd3 Compare August 27, 2026 02:29
@red-hat-konflux
red-hat-konflux Bot merged commit ee3a6a0 into release-0.3 Aug 27, 2026
27 checks passed
@red-hat-konflux
red-hat-konflux Bot deleted the konflux/mintmaker/release-0.3/lock-file-maintenance-vulnerability branch August 27, 2026 03:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant