Refresh RPM lockfiles [SECURITY] #463
Open
+239
−212
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
File tools/rpm-manifests/rpms.in.yaml:
2:1.14.0-1.el9->2:1.16.0-1.el92:1.39.4-2.el9_6->2:1.41.4-3.el9_73:2.1.12-1.el9->3:2.1.13-1.el92:1-117.el9_6->4:1-135.el9_72:1-117.el9_6->4:1-135.el9_73.19-1.el9->3.19-3.el93.19-1.el9->3.19-3.el91.23.1-2.el9_6->1.23.1-2.el9_71.14-1.el9->1.15-1.el92:1.14.1-1.el9_6->2:1.16.0-1.el90^20250217.ga1e48a0-10.el9_6->0^20250512.g8ec1341-2.el95:5.4.0-13.el9_6->6:5.6.0-6.el9_73.11.11-2.el9_6.2->3.11.13-3.el93.11.11-2.el9_6.2->3.11.13-3.el922.3.1-5.el9->22.3.1-6.el965.5.1-4.el9_6->65.5.1-5.el91.3.2-1.el9->1.3.3-1.el91.6-17.el9_6.2->1.6-19.el928-10.el9->28-11.el9590-5.el9->590-6.el91:1.0.9-3.el9->1:1.0.9-5.el9_78.7p1-45.el9->8.7p1-46.el98.7p1-45.el9->8.7p1-46.el91:3.2.2-6.el9_5.1->1:3.5.1-3.el92:4.9-12.el9->2:4.9-15.el9Warning
Some dependencies could not be looked up. Check the warning logs for more information.
cpython: Cpython infinite loop when parsing a tarfile
CVE-2025-8194
More information
Details
A flaw was found in the Python tarfile module. Processing a specially crafted tar archive, specifically an archive with negative offsets, can cause an infinite loop and deadlock. This issue results in a denial of service in the Python application using the tarfile module.
Severity
Moderate
References
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.