Skip to content

Conversation

red-hat-konflux-kflux-prd-rh03[bot]
Copy link
Contributor

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot commented Sep 10, 2025

This PR contains the following updates:

File rpms.in.yaml:

Package Change
adwaita-cursor-theme 48.0-1.fc42 -> 48.1-1.fc42
adwaita-icon-theme 48.0-1.fc42 -> 48.1-1.fc42
apr-util 1.6.3-22.fc42 -> 1.6.3-25.fc42
apr-util-lmdb 1.6.3-22.fc42 -> 1.6.3-25.fc42
apr-util-openssl 1.6.3-22.fc42 -> 1.6.3-25.fc42
expat 2.7.1-1.fc42 -> 2.7.2-1.fc42
libaom 3.12.0-1.fc42 -> 3.13.1-1.fc42
libjpeg-turbo 3.1.0-2.fc42 -> 3.1.2-1.fc42
libopenmpt 0.7.13-3.fc42 -> 0.8.3-1.fc42
python-pip-wheel 24.3.1-2.fc42 -> 24.3.1-5.fc42
amd-gpu-firmware 20250808-1.fc42 -> 20250917-2.fc42
amd-ucode-firmware 20250808-1.fc42 -> 20250917-2.fc42
at-spi2-atk 2.56.3-1.fc42 -> 2.56.5-1.fc42
at-spi2-core 2.56.3-1.fc42 -> 2.56.5-1.fc42
atheros-firmware 20250808-1.fc42 -> 20250917-2.fc42
atk 2.56.3-1.fc42 -> 2.56.5-1.fc42
bluez-libs 5.83-2.fc42 -> 5.84-2.fc42
bootc 1.6.0-1.fc42 -> 1.8.0-1.fc42
bootupd 0.2.29-1.fc42 -> 0.2.30-1.fc42
brcmfmac-firmware 20250808-1.fc42 -> 20250917-2.fc42
btrfs-progs 6.16-1.fc42 -> 6.16.1-1.fc42
buildah 2:1.41.3-1.fc42 -> 2:1.41.5-1.fc42
butane 0.24.0-1.fc42 -> 0.25.1-1.fc42
cirrus-audio-firmware 20250808-1.fc42 -> 20250917-2.fc42
container-selinux 4:2.241.0-1.fc42 -> 4:2.242.0-1.fc42
containers-common 5:0.64.1-2.fc42 -> 5:0.64.2-1.fc42
containers-common-extra 5:0.64.1-2.fc42 -> 5:0.64.2-1.fc42
crun 1.23.1-1.fc42 -> 1.24-1.fc42
cups-filesystem 1:2.4.12-3.fc42 -> 1:2.4.14-2.fc42
cups-libs 1:2.4.12-3.fc42 -> 1:2.4.14-2.fc42
dracut 107-2.fc42 -> 107-4.fc42
edk2-aarch64 20250523-14.fc42 -> 20250523-16.fc42
edk2-ovmf 20250523-14.fc42 -> 20250523-16.fc42
edk2-shell-aa64 20250523-14.fc42 -> 20250523-16.fc42
edk2-shell-x64 20250523-14.fc42 -> 20250523-16.fc42
go-filesystem 3.7.0-1.fc42 -> 3.8.0-1.fc42
go-srpm-macros 3.7.0-1.fc42 -> 3.8.0-1.fc42
golang 1.24.6-1.fc42 -> 1.24.7-1.fc42
golang-bin 1.24.6-1.fc42 -> 1.24.7-1.fc42
golang-src 1.24.6-1.fc42 -> 1.24.7-1.fc42
gstreamer1 1.26.5-2.fc42 -> 1.26.6-1.fc42
gstreamer1-plugins-base 1.26.5-1.fc42 -> 1.26.6-1.fc42
ignition-validate 2.22.0-3.fc42 -> 2.23.0-1.fc42
intel-audio-firmware 20250808-1.fc42 -> 20250917-2.fc42
intel-gpu-firmware 20250808-1.fc42 -> 20250917-2.fc42
intel-vpl-gpu-rt 25.3.2-1.fc42 -> 25.3.4-1.fc42
kernel-core 6.16.3-200.fc42 -> 6.16.9-200.fc42
kernel-modules 6.16.3-200.fc42 -> 6.16.9-200.fc42
kernel-modules-core 6.16.3-200.fc42 -> 6.16.9-200.fc42
libavcodec-free 7.1.1-4.fc42 -> 7.1.2-1.fc42
libavformat-free 7.1.1-4.fc42 -> 7.1.2-1.fc42
libavutil-free 7.1.1-4.fc42 -> 7.1.2-1.fc42
libgexiv2 0.14.5-1.fc42 -> 0.14.6-1.fc42
libnfsidmap 1:2.8.3-2.rc3.fc42 -> 1:2.8.4-0.fc42
libselinux-utils 3.8-2.fc42 -> 3.8-3.fc42
libsoup3 3.6.5-2.fc42 -> 3.6.5-6.fc42
libswresample-free 7.1.1-4.fc42 -> 7.1.2-1.fc42
linux-firmware 20250808-1.fc42 -> 20250917-2.fc42
linux-firmware-whence 20250808-1.fc42 -> 20250917-2.fc42
mesa-dri-drivers 25.1.7-1.fc42 -> 25.1.9-1.fc42
mesa-filesystem 25.1.7-1.fc42 -> 25.1.9-1.fc42
mesa-libEGL 25.1.7-1.fc42 -> 25.1.9-1.fc42
mesa-libGL 25.1.7-1.fc42 -> 25.1.9-1.fc42
mesa-libgbm 25.1.7-1.fc42 -> 25.1.9-1.fc42
mesa-va-drivers 25.1.7-1.fc42 -> 25.1.9-1.fc42
mesa-vulkan-drivers 25.1.7-1.fc42 -> 25.1.9-1.fc42
mt7xxx-firmware 20250808-1.fc42 -> 20250917-2.fc42
nbdkit 1.42.7-1.fc42 -> 1.42.8-1.fc42
nbdkit-basic-filters 1.42.7-1.fc42 -> 1.42.8-1.fc42
nbdkit-basic-plugins 1.42.7-1.fc42 -> 1.42.8-1.fc42
nbdkit-curl-plugin 1.42.7-1.fc42 -> 1.42.8-1.fc42
nbdkit-selinux 1.42.7-1.fc42 -> 1.42.8-1.fc42
nbdkit-server 1.42.7-1.fc42 -> 1.42.8-1.fc42
nbdkit-ssh-plugin 1.42.7-1.fc42 -> 1.42.8-1.fc42
nfs-utils 1:2.8.3-2.rc3.fc42 -> 1:2.8.4-0.fc42
nvidia-gpu-firmware 20250808-1.fc42 -> 20250917-2.fc42
nxpwireless-firmware 20250808-1.fc42 -> 20250917-2.fc42
openjpeg 2.5.3-8.fc42 -> 2.5.4-1.fc42
osbuild 158-1.fc42 -> 161-1.fc42
osbuild-ostree 158-1.fc42 -> 161-1.fc42
osbuild-selinux 158-1.fc42 -> 161-1.fc42
osbuild-tools 158-1.fc42 -> 161-1.fc42
ostree 2025.4-2.fc42 -> 2025.6-1.fc42
ostree-libs 2025.4-2.fc42 -> 2025.6-1.fc42
pango 1.56.4-1.fc42 -> 1.56.4-2.fc42
passt 0^20250805.g309eefd-2.fc42 -> 0^20250919.g623dbf6-1.fc42
passt-selinux 0^20250805.g309eefd-2.fc42 -> 0^20250919.g623dbf6-1.fc42
pipewire 1.4.7-1.fc42 -> 1.4.8-2.fc42
pipewire-alsa 1.4.7-1.fc42 -> 1.4.8-2.fc42
pipewire-jack-audio-connection-kit 1.4.7-1.fc42 -> 1.4.8-2.fc42
pipewire-jack-audio-connection-kit-libs 1.4.7-1.fc42 -> 1.4.8-2.fc42
pipewire-libs 1.4.7-1.fc42 -> 1.4.8-2.fc42
pipewire-plugin-libcamera 1.4.7-1.fc42 -> 1.4.8-2.fc42
pipewire-pulseaudio 1.4.7-1.fc42 -> 1.4.8-2.fc42
podman 5:5.6.0-1.fc42 -> 5:5.6.2-1.fc42
poppler 25.02.0-2.fc42 -> 25.02.0-3.fc42
poppler-glib 25.02.0-2.fc42 -> 25.02.0-3.fc42
pyproject-srpm-macros 1.18.3-1.fc42 -> 1.18.4-1.fc42
python3-boto3 1.40.22-1.fc42 -> 1.40.43-1.fc42
python3-botocore 1.40.22-1.fc42 -> 1.40.43-1.fc42
python3-copr 2.2-1.fc42 -> 2.3-1.fc42
python3-fedfind 6.1.0-1.fc42 -> 6.1.1-1.fc42
python3-libselinux 3.8-2.fc42 -> 3.8-3.fc42
python3-osbuild 158-1.fc42 -> 161-1.fc42
python3-s3transfer 0.13.1-1.fc42 -> 0.14.0-1.fc42
qcom-wwan-firmware 20250808-1.fc42 -> 20250917-2.fc42
qemu-audio-alsa 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-audio-dbus 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-audio-jack 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-audio-oss 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-audio-pa 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-audio-pipewire 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-audio-sdl 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-audio-spice 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-block-blkio 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-block-curl 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-block-dmg 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-block-gluster 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-block-iscsi 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-block-nfs 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-block-rbd 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-block-ssh 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-char-baum 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-char-spice 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-common 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-qxl 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-vhost-user-gpu 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-gpu 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-gpu-ccw 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-gpu-gl 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-gpu-pci 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-gpu-pci-gl 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-gpu-pci-rutabaga 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-gpu-rutabaga 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-vga 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-vga-gl 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-display-virtio-vga-rutabaga 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-usb-host 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-usb-redirect 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-device-usb-smartcard 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-img 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-kvm 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-kvm-core 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-pr-helper 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-system-aarch64-core 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-system-ppc-core 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-system-s390x-core 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-system-x86 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-system-x86-core 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-ui-curses 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-ui-egl-headless 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-ui-gtk 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-ui-opengl 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-ui-sdl 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-ui-spice-app 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-ui-spice-core 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-aarch64 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-alpha 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-arm 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-hexagon 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-hppa 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-loongarch64 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-m68k 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-microblaze 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-mips 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-or1k 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-ppc 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-riscv 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-s390x 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-sh4 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-sparc 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-x86 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qemu-user-static-xtensa 2:9.2.4-1.fc42 -> 2:9.2.4-2.fc42
qt6-srpm-macros 6.9.1-1.fc42 -> 6.9.2-1.fc42
realtek-firmware 20250808-1.fc42 -> 20250917-2.fc42
selinux-policy 42.7-1.fc42 -> 42.9-1.fc42
selinux-policy-targeted 42.7-1.fc42 -> 42.9-1.fc42
skopeo 1:1.20.0-1.fc42 -> 1:1.20.0-3.fc42
systemd 257.7-1.fc42 -> 257.9-2.fc42
systemd-container 257.7-1.fc42 -> 257.9-2.fc42
systemd-networkd 257.7-1.fc42 -> 257.9-2.fc42
systemd-pam 257.7-1.fc42 -> 257.9-2.fc42
systemd-resolved 257.7-1.fc42 -> 257.9-2.fc42
systemd-rpm-macros 257.7-1.fc42 -> 257.9-2.fc42
systemd-shared 257.7-1.fc42 -> 257.9-2.fc42
systemd-udev 257.7-1.fc42 -> 257.9-2.fc42
tiwilink-firmware 20250808-1.fc42 -> 20250917-2.fc42
wireplumber 0.5.10-1.fc42 -> 0.5.11-1.fc42
wireplumber-libs 0.5.10-1.fc42 -> 0.5.11-1.fc42
xen-libs 4.19.3-2.fc42 -> 4.19.3-4.fc42
xen-licenses 4.19.3-2.fc42 -> 4.19.3-4.fc42
rpm-ostree 2025.10-2.fc42 -> 2025.11-1.fc42
rpm-ostree-libs 2025.10-2.fc42 -> 2025.11-1.fc42

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


net/http: Request smuggling due to acceptance of invalid chunked data in net/http

CVE-2025-22871

More information

Details

A flaw was found in the net/http golang package. The net/http package incorrectly accepts messages that end with a line feed (LF) instead of the proper line ending. When used with another server that also misinterprets this, it can lead to request smuggling—where an attacker tricks the system to send hidden or unauthorized requests.

Severity

Moderate

References


cmd/go: Go VCS Command Execution Vulnerability

CVE-2025-4674

More information

Details

A flaw was found in cmd/go. The go command can execute arbitrary commands when processing untrusted version control system (VCS) repositories containing malicious configuration. This issue occurs because the command interprets VCS metadata, potentially leading to unintended command execution. This vulnerability allows a malicious actor to trigger this by providing a repository with a crafted VCS configuration, resulting in arbitrary code execution within the context of the go process.

Severity

Important

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.

This PR has been generated by MintMaker (powered by Renovate Bot).

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 5 times, most recently from d7e73b0 to eaa3860 Compare September 12, 2025 04:06
jbtrystram
jbtrystram previously approved these changes Sep 12, 2025
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 13 times, most recently from d35a15a to b1a3d21 Compare September 19, 2025 20:05
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 10 times, most recently from 3a0dde6 to 043c3d2 Compare September 27, 2025 00:06
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot changed the title chore(deps): refresh rpm lockfiles [SECURITY] Refresh RPM lockfiles [SECURITY] Sep 27, 2025
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 3 times, most recently from 3856286 to 62be7cb Compare September 29, 2025 16:06
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot changed the title Refresh RPM lockfiles [SECURITY] chore(deps): refresh rpm lockfiles [SECURITY] Sep 29, 2025
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch 6 times, most recently from f83d1ad to 3796302 Compare October 4, 2025 04:04
Signed-off-by: red-hat-konflux-kflux-prd-rh03 <206760901+red-hat-konflux-kflux-prd-rh03[bot]@users.noreply.github.com>
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 bot force-pushed the renovate/main/lock-file-maintenance-vulnerability branch from 3796302 to c51d7c2 Compare October 5, 2025 04:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant