Skip to content

Conversation

konflux-internal-p02[bot]
Copy link

@konflux-internal-p02 konflux-internal-p02 bot commented Sep 11, 2025

This PR contains the following updates:

Package Update Change
python3.11-devel patch 3.11.11-2.el9_6.2 -> 3.11.13-2.el8_10

cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

CVE-2025-4138

More information

Severity

Important

References


cpython: Tarfile extracts filtered members when errorlevel=0

CVE-2025-4435

More information

Severity

Important

References


cpython: python: Bypass extraction filter to modify file metadata outside extraction directory

CVE-2024-12718

More information

Severity

Important

References


python: cpython: Arbitrary writes via tarfile realpath overflow

CVE-2025-4517

More information

Severity

Important

References


cpython: python: Extraction filter bypass for linking outside extraction directory

CVE-2025-4330

More information

Severity

Important

References


cpython: Cpython infinite loop when parsing a tarfile

CVE-2025-8194

More information

Severity

Moderate

References


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled because a matching PR was automerged previously.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.

This PR has been generated by MintMaker (powered by Renovate Bot).

@konflux-internal-p02 konflux-internal-p02 bot force-pushed the renovate/rpm/rhoai-2.22/rpm-lockfile-python3.11-devel-vulnerability branch 30 times, most recently from 2a8115f to d992a65 Compare September 16, 2025 04:36
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the renovate/rpm/rhoai-2.22/rpm-lockfile-python3.11-devel-vulnerability branch 24 times, most recently from 42b4ac1 to 27f611b Compare September 23, 2025 00:38
Signed-off-by: konflux-internal-p02 <170854209+konflux-internal-p02[bot]@users.noreply.github.com>
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the renovate/rpm/rhoai-2.22/rpm-lockfile-python3.11-devel-vulnerability branch from 27f611b to eaa3a8a Compare September 23, 2025 00:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants