Skip to content

Conversation

@red-hat-konflux
Copy link
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
aardvark-dns 2:1.14.0-1.el9 -> 2:1.16.0-1.el9
buildah 2:1.39.4-2.el9_6 -> 2:1.41.4-3.el9_7
containers-common 2:1-117.el9_6 -> 4:1-135.el9_7
containers-common-extra 2:1-117.el9_6 -> 4:1-135.el9_7
criu 3.19-1.2.el9_6 -> 3.19-3.el9
criu-libs 3.19-1.2.el9_6 -> 3.19-3.el9
crun 1.23.1-2.el9_6 -> 1.23.1-2.el9_7
fuse-overlayfs 1.14-1.el9 -> 1.15-1.el9
netavark 2:1.14.1-1.el9_6 -> 2:1.16.0-1.el9
passt 0^20250217.ga1e48a0-13.el9_6 -> 0^20250512.g8ec1341-2.el9
python3.11 3.11.11-2.el9_6.2 -> 3.11.13-3.el9
python3.11-libs 3.11.11-2.el9_6.2 -> 3.11.13-3.el9
python3.11-pip 22.3.1-5.el9 -> 22.3.1-6.el9
python3.11-pip-wheel 22.3.1-5.el9 -> 22.3.1-6.el9
python3.11-setuptools 65.5.1-4.el9_6 -> 65.5.1-5.el9
python3.11-setuptools-wheel 65.5.1-4.el9_6 -> 65.5.1-5.el9
slirp4netns 1.3.2-1.el9 -> 1.3.3-1.el9
kmod 28-10.el9 -> 28-11.el9
nftables 1:1.0.9-4.el9_6 -> 1:1.0.9-5.el9_7
shadow-utils-subid 2:4.9-12.el9 -> 2:4.9-15.el9

cpython: Cpython infinite loop when parsing a tarfile

CVE-2025-8194

More information

Details

A flaw was found in the Python tarfile module. Processing a specially crafted tar archive, specifically an archive with negative offsets, can cause an infinite loop and deadlock. This issue results in a denial of service in the Python application using the tarfile module.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@openshift-ci openshift-ci bot requested review from bparees and syedriko November 11, 2025 16:19
@syedriko
Copy link
Contributor

/retest
/lgtm
/approve
/override ci/prow/images

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Nov 11, 2025
@openshift-ci
Copy link

openshift-ci bot commented Nov 11, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: syedriko

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Nov 11, 2025
@openshift-ci
Copy link

openshift-ci bot commented Nov 11, 2025

@syedriko: Overrode contexts on behalf of syedriko: ci/prow/images

In response to this:

/retest
/lgtm
/approve
/override ci/prow/images

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from 7b54f60 to fc5d88c Compare November 11, 2025 20:18
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Nov 11, 2025
@openshift-ci
Copy link

openshift-ci bot commented Nov 11, 2025

New changes are detected. LGTM label has been removed.

@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from fc5d88c to 127195d Compare November 12, 2025 20:21
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/main/lock-file-maintenance-vulnerability branch from 127195d to 5ce4308 Compare November 15, 2025 00:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant