chore(deps): refresh rpm lockfiles [SECURITY] - #3360
Open
red-hat-konflux[bot] wants to merge 1 commit into
Open
Conversation
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/release-3.23/lock-file-maintenance-vulnerability
branch
from
May 27, 2026 14:17
069c168 to
3d50287
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release-3.23 #3360 +/- ##
=============================================
Coverage 27.61% 27.61%
=============================================
Files 96 96
Lines 5424 5424
Branches 2523 2523
=============================================
Hits 1498 1498
Misses 3214 3214
Partials 712 712
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |
jschnath
approved these changes
Jun 11, 2026
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/release-3.23/lock-file-maintenance-vulnerability
branch
2 times, most recently
from
July 23, 2026 09:36
ff890ae to
56f30df
Compare
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/release-3.23/lock-file-maintenance-vulnerability
branch
from
July 29, 2026 21:55
56f30df to
3ecb40b
Compare
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/release-3.23/lock-file-maintenance-vulnerability
branch
from
August 14, 2026 02:51
3ecb40b to
b9c6397
Compare
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/release-3.23/lock-file-maintenance-vulnerability
branch
from
August 14, 2026 06:09
b9c6397 to
5a18ec6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
File rpms.in.yaml:
049-244.git20260529.el8_10->049-246.git20260728.el8_104.18.0-553.154.1.el8_10->4.18.0-553.155.1.el8_10dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()
CVE-2026-15816
More information
Details
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
Severity
Important
References
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (in timezone Etc/UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.