chore(deps): rpm updates [security] #2330
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.9.7-21.el8_10.2->2.9.7-21.el8_10.3libxml: Heap use after free (UAF) leads to Denial of service (DoS)
CVE-2025-49794
More information
Severity
Important
References
libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
CVE-2025-6021
More information
Severity
Important
References
libxml: Type confusion leads to Denial of service (DoS)
CVE-2025-49796
More information
Severity
Important
References
libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
CVE-2025-7425
More information
Severity
Important
References
libxml2: XXE vulnerability
CVE-2024-40896
More information
Severity
Critical
References
libxml: Null pointer dereference leads to Denial of service (DoS)
CVE-2025-49795
More information
Severity
Important
References
Configuration
📅 Schedule: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.This PR has been generated by MintMaker (powered by Renovate Bot).