[ALSA-2024:2961] Moderate: Image builder components bug fix, enhancement and security update
Type:
security
Severity:
moderate
Release date:
2024-05-29
Description:
Image Builder is a service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Security Fix(es): * osbuild-composer: race condition may disable GPG verification for package repositories (CVE-2024-2307) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 osbuild-composer-worker-101-1.el8.alma.1.aarch64.rpm 3f59d172741baab8bdbf22ac85db25cf240ca145a606a3b493126f168191ed12
aarch64 osbuild-composer-101-1.el8.alma.1.aarch64.rpm b2a4a20959c0840843f125404165202cca971a12861d83d6080bff7530dc6e53
aarch64 osbuild-composer-core-101-1.el8.alma.1.aarch64.rpm b39ad4da7de57a98f8639dddeab949fd3760a695cd89d0c99118a26ee4f57fba
ppc64le osbuild-composer-worker-101-1.el8.alma.1.ppc64le.rpm 20c106ead71d8569a454987fe6a259651758d0ab88c5fc04f3a6ecde5d256b73
ppc64le osbuild-composer-core-101-1.el8.alma.1.ppc64le.rpm 31fb996ae33ac8e21f37c825527e25200c44f6406909bffa9b10d2f56ffdb4ce
ppc64le osbuild-composer-101-1.el8.alma.1.ppc64le.rpm 3a00943f3f35e479f698c1dba93eae0696754cc69ac43fc60cff05645a2046c9
s390x osbuild-composer-101-1.el8.alma.1.s390x.rpm a1fbb0097bf3eb1b14c5a04f12d63f29296c9b2216b8a2651a110c53734b8e38
s390x osbuild-composer-core-101-1.el8.alma.1.s390x.rpm bc5bae12773b79a04fc0c1d9de04860cf7ddf4904252f08dc3e278527809cce6
s390x osbuild-composer-worker-101-1.el8.alma.1.s390x.rpm e51891da927085400f933bbfb1a45c1739ba36f20771b859d77f8ef740310a48
x86_64 osbuild-composer-worker-101-1.el8.alma.1.x86_64.rpm 5ed9a4e0e9dd81c5d5d6d6197745655662c1ad9647fcadd1bf7cb848ffbd7521
x86_64 osbuild-composer-core-101-1.el8.alma.1.x86_64.rpm 8f48a837f77e1d76f043b1cb533fb08ada4b3a3a4d964729eb746e39f92271d6
x86_64 osbuild-composer-101-1.el8.alma.1.x86_64.rpm b8f1381b32ca35d20a64221dce4911c4513931e6d38b94503b38506044b8fd64
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.