Skip to content

chore(deps): refresh rpm lockfiles (foreman-3.16) [SECURITY]#2166

Closed
red-hat-konflux[bot] wants to merge 1 commit intoforeman-3.16from
konflux/mintmaker/foreman-3.16-foreman-3.16/foreman-satellite-base-updates-vulnerability
Closed

chore(deps): refresh rpm lockfiles (foreman-3.16) [SECURITY]#2166
red-hat-konflux[bot] wants to merge 1 commit intoforeman-3.16from
konflux/mintmaker/foreman-3.16-foreman-3.16/foreman-satellite-base-updates-vulnerability

Conversation

@red-hat-konflux
Copy link
Copy Markdown
Contributor

@red-hat-konflux red-hat-konflux Bot commented Jan 16, 2026

This PR contains the following updates:

File .hermetic_builds/rpms.in.yaml:

Package Change
kernel-headers 5.14.0-611.20.1.el9_7 -> 5.14.0-611.24.1.el9_7
postgresql 16.10-1.module+el9.7.0+23477+80afd791 -> 16.11-1.module+el9.7.0+23784+0c5a3b34
postgresql-private-libs 16.10-1.module+el9.7.0+23477+80afd791 -> 16.11-1.module+el9.7.0+23784+0c5a3b34
postgresql-server 16.10-1.module+el9.7.0+23477+80afd791 -> 16.11-1.module+el9.7.0+23784+0c5a3b34

postgresql: libpq: libpq undersizes allocations, via integer wraparound

CVE-2025-12818

More information

Details

A vulnerability has been identified in PostgreSQL’s libpq client library, where integer wraparound in several allocation-size calculations allows a peer or input provider to cause an undersized buffer and then write out-of-bounds by hundreds of megabytes. This can lead to a client application segmentation fault or crash when using libpq to connect to a PostgreSQL server.

Severity

Moderate

References


postgresql: CREATE STATISTICS does not check for schema CREATE privilege

CVE-2025-12817

More information

Details

A vulnerability has been identified in PostgreSQL’s CREATE STATISTICS command where the database does not check that the user has the required schema CREATE privilege. A table owner user could create a statistics object in any schema, blocking other users who legitimately hold CREATE STATISTICS permissions from creating objects with the same name. This results in a denial-of-service of the statistics creation functionality.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Prague, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@jira-linking
Copy link
Copy Markdown

jira-linking Bot commented Jan 16, 2026

Commits missing Jira IDs:
e5d46fe

@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/foreman-3.16-foreman-3.16/foreman-satellite-base-updates-vulnerability branch 23 times, most recently from 1d1b1ab to 8a0a4ee Compare January 22, 2026 12:46
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux Bot force-pushed the konflux/mintmaker/foreman-3.16-foreman-3.16/foreman-satellite-base-updates-vulnerability branch from 8a0a4ee to e5d46fe Compare January 22, 2026 12:46
@jdobes jdobes closed this Feb 12, 2026
@jdobes jdobes deleted the konflux/mintmaker/foreman-3.16-foreman-3.16/foreman-satellite-base-updates-vulnerability branch February 18, 2026 12:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant