[ALSA-2026:13643] Important: osbuild-composer security update
Type:
security
Severity:
important
Release date:
2026-05-06
Description:
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 osbuild-composer-core-149-6.el10_1.alma.3.aarch64.rpm 3427b98c25c8ed4da71a6b656a4200b7972a0dd69bea769687872aea30157570
aarch64 osbuild-composer-worker-149-6.el10_1.alma.3.aarch64.rpm 89058db201b99fcd94f0c26581aefa175cfd59bcbfd19078a30ada97fc5c2c17
aarch64 osbuild-composer-149-6.el10_1.alma.3.aarch64.rpm e1110b9b020b7859e67b9df4803e257dfc0226122371a47a0503ab55f253d63e
ppc64le osbuild-composer-core-149-6.el10_1.alma.3.ppc64le.rpm 458571aa1addbd730d9b64a8e95d775e6e7a05c2962ff787a3f754596b78cd38
ppc64le osbuild-composer-worker-149-6.el10_1.alma.3.ppc64le.rpm 9eca3eb1df4f1a653f2b8baeeaa717396bf531d560b96997e154af87bce734c5
ppc64le osbuild-composer-149-6.el10_1.alma.3.ppc64le.rpm d82810f07efe9fe6da13dacef38c7c0a88e90b7e8502e70dea39a2e632b3f269
s390x osbuild-composer-worker-149-6.el10_1.alma.3.s390x.rpm ca2392090bbaa06748c3feefa0875c4a85b696a7237ac5cf4dba2f7ad537f01f
s390x osbuild-composer-149-6.el10_1.alma.3.s390x.rpm ce8766cda3828ca471e6ff0f4edf4c90679ea5928982b226443be0d6ecef8cf8
s390x osbuild-composer-core-149-6.el10_1.alma.3.s390x.rpm dc28376ed99a61977a7b526bbf6432da4d79282c7384b354a987cf93167d49ea
x86_64 osbuild-composer-worker-149-6.el10_1.alma.3.x86_64.rpm 73f5122b0b5ef96bfb2319946cef836cd1d430e82209ef7af5baad9edd1e880f
x86_64 osbuild-composer-core-149-6.el10_1.alma.3.x86_64.rpm cf3f2b5cc5b55a82919c8fc59458758e7231aa1641004af553c16ca32e61d17d
x86_64 osbuild-composer-149-6.el10_1.alma.3.x86_64.rpm d397763228af2f4a0de4852ae8d65b092d1589056531c11a37e2f8b43b21ec5b
x86_64_v2 osbuild-composer-149-6.el10_1.alma.3.x86_64_v2.rpm 2e45c124f73f07c6eeea2e50a3caae2aee9ec2462b0b13d3e6568227346003ef
x86_64_v2 osbuild-composer-core-149-6.el10_1.alma.3.x86_64_v2.rpm 310ec9310bb7399445e8e43f03c63cdf0dab00037dc6fb698dbc54904bcfefd3
x86_64_v2 osbuild-composer-worker-149-6.el10_1.alma.3.x86_64_v2.rpm 53b2fb8e9e92ed0e52d2909b8488cf2db6f636bb83080fad66e286b6fdb84bd4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.