Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#2912

Merged
red-hat-konflux[bot] merged 2 commits intorelease-3.22from
konflux/mintmaker/release-3.22/lock-file-maintenance-vulnerability
Feb 16, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#2912
red-hat-konflux[bot] merged 2 commits intorelease-3.22from
konflux/mintmaker/release-3.22/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux
Copy link
Contributor

@red-hat-konflux red-hat-konflux bot commented Feb 12, 2026

This PR contains the following updates:

File rpms.in.yaml:

Package Change
gcc-toolset-14-binutils 2.41-4.el8_10 -> 2.41-4.el8_10.1
kernel-headers 4.18.0-553.104.1.el8_10 -> 4.18.0-553.105.1.el8_10

binutils: GNU Binutils Linker heap-based overflow

CVE-2025-11083

More information

Details

A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux bot requested review from a team and rhacs-bot as code owners February 12, 2026 13:09
@red-hat-konflux red-hat-konflux bot enabled auto-merge (squash) February 12, 2026 13:09
Copy link
Contributor

@rhacs-bot rhacs-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@codecov-commenter
Copy link

codecov-commenter commented Feb 12, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 27.61%. Comparing base (a3ead3e) to head (d8d5dc4).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@              Coverage Diff              @@
##           release-3.22    #2912   +/-   ##
=============================================
  Coverage         27.61%   27.61%           
=============================================
  Files                96       96           
  Lines              5424     5424           
  Branches           2523     2523           
=============================================
  Hits               1498     1498           
  Misses             3214     3214           
  Partials            712      712           
Flag Coverage Δ
collector-unit-tests 27.61% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@mclasmeier
Copy link

/retest

@msugakov msugakov added the optional Nice to have feature, but not a blocker label Feb 12, 2026
@github-actions
Copy link

/retest collector-on-push

@mclasmeier mclasmeier removed the optional Nice to have feature, but not a blocker label Feb 12, 2026
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/release-3.22/lock-file-maintenance-vulnerability branch from 5f087af to 531eda3 Compare February 16, 2026 13:10
@mclasmeier mclasmeier added the optional Nice to have feature, but not a blocker label Feb 16, 2026
@github-actions
Copy link

/retest collector-on-push

@red-hat-konflux
Copy link
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@github-actions
Copy link

/retest collector-on-push

@red-hat-konflux red-hat-konflux bot merged commit a7d8978 into release-3.22 Feb 16, 2026
80 of 81 checks passed
@red-hat-konflux red-hat-konflux bot deleted the konflux/mintmaker/release-3.22/lock-file-maintenance-vulnerability branch February 16, 2026 19:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-approve build-builder-image optional Nice to have feature, but not a blocker rebuild-test-container Rebuild the collector-tests container.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Comments