[ALSA-2026:2124] Important: osbuild-composer security update
Type:
security
Severity:
important
Release date:
2026-02-09
Description:
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 osbuild-composer-core-101.4-3.el8_10.alma.1.aarch64.rpm 95c13f35e6599139f77d40293a05d2c1aa62f0a6d7bbfb7532580e7d8d7db2da
aarch64 osbuild-composer-worker-101.4-3.el8_10.alma.1.aarch64.rpm c46e735469155f3a8cfdbba601f40800fea8a448f0f10b012672c2dcdda320de
aarch64 osbuild-composer-101.4-3.el8_10.alma.1.aarch64.rpm d58689a41445c8c6cacdc4111e65fcbc91dcaccfc0f07dfa4be360022a7ba19b
ppc64le osbuild-composer-core-101.4-3.el8_10.alma.1.ppc64le.rpm 629a671090e105c5cd7a3135535680c32a4d4b0f2789d8c1c083d9f81f6d99ba
ppc64le osbuild-composer-worker-101.4-3.el8_10.alma.1.ppc64le.rpm 92ea5e9bf1b6e75c68d3f9ea100da3bbf1cb040ba9cf53f3f8f60ca8f05d2506
ppc64le osbuild-composer-101.4-3.el8_10.alma.1.ppc64le.rpm aa50cf51f57a706c1799421516d7fc5633ff17ea899c9e5f4ea2b1d38f7359df
s390x osbuild-composer-core-101.4-3.el8_10.alma.1.s390x.rpm 2cf7edc20d7a07fdca4d761245ac24e724237945c7efaa1105ff38588a3ef289
s390x osbuild-composer-101.4-3.el8_10.alma.1.s390x.rpm 74f48f3399752cfa277b1c1d846ce4a0e200af9ca6ff7068245c2aea74f1fcbc
s390x osbuild-composer-worker-101.4-3.el8_10.alma.1.s390x.rpm d26591cfc2fb97876dbfc748011e69de2da83562f8cf342737231b3f965606da
x86_64 osbuild-composer-core-101.4-3.el8_10.alma.1.x86_64.rpm 31edadd50ff1c358875c7e738881907da36a6ce47a1381b6b5002e2c64d33228
x86_64 osbuild-composer-101.4-3.el8_10.alma.1.x86_64.rpm de79e6f6fbbd543a3731b3abd27a18761b733516266b77f713c4f20fc3956ce3
x86_64 osbuild-composer-worker-101.4-3.el8_10.alma.1.x86_64.rpm eb49e27d2a1cef3d86ca8022f468d5f60642bf477ea1a66b1d5467fad0977799
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.