Skip to content

Conversation

konflux-internal-p02[bot]
Copy link

@konflux-internal-p02 konflux-internal-p02 bot commented Sep 11, 2025

This PR contains the following updates:

Package Update Change
python3.11-libs patch 3.11.11-2.el9_6.2 -> 3.11.13-2.el8_10

python: cpython: Arbitrary writes via tarfile realpath overflow

CVE-2025-4517

More information

Severity

Important

References


cpython: python: Bypass extraction filter to modify file metadata outside extraction directory

CVE-2024-12718

More information

Severity

Important

References


cpython: python: Extraction filter bypass for linking outside extraction directory

CVE-2025-4330

More information

Severity

Important

References


cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

CVE-2025-4138

More information

Severity

Important

References


cpython: Tarfile extracts filtered members when errorlevel=0

CVE-2025-4435

More information

Severity

Important

References


cpython: Cpython infinite loop when parsing a tarfile

CVE-2025-8194

More information

Severity

Moderate

References


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled because a matching PR was automerged previously.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.

This PR has been generated by MintMaker (powered by Renovate Bot).

@konflux-internal-p02 konflux-internal-p02 bot force-pushed the renovate/rpm/rhoai-2.22/rpm-lockfile-python3.11-libs-vulnerability branch 26 times, most recently from c0bdb62 to e273185 Compare September 16, 2025 04:36
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the renovate/rpm/rhoai-2.22/rpm-lockfile-python3.11-libs-vulnerability branch 4 times, most recently from 03898cc to 4f938d7 Compare September 18, 2025 20:32
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the renovate/rpm/rhoai-2.22/rpm-lockfile-python3.11-libs-vulnerability branch 22 times, most recently from 9325565 to e4082a6 Compare September 23, 2025 00:38
Signed-off-by: konflux-internal-p02 <170854209+konflux-internal-p02[bot]@users.noreply.github.com>
@konflux-internal-p02 konflux-internal-p02 bot force-pushed the renovate/rpm/rhoai-2.22/rpm-lockfile-python3.11-libs-vulnerability branch from e4082a6 to 8ae9dc6 Compare September 23, 2025 00:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants