[ALSA-2026:66016] Important: osbuild-composer security update
Type:
security
Severity:
important
Release date:
2026-09-10
Description:
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355) * golang: net/[http:](http:) net/[http:](http:) sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * golang.org/x/net/idna: golang: net/[http:](http:) golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 osbuild-composer-101.5-2.el8_10.alma.1.aarch64.rpm c35bd60b3a4fd4014893685a961c3024aa0ccf2a2a8fb91cd73eced248440462
aarch64 osbuild-composer-core-101.5-2.el8_10.alma.1.aarch64.rpm cfa469626f29b5763c7e3cab94c66f9cddf867017e8db927a527caf7d7507cae
aarch64 osbuild-composer-worker-101.5-2.el8_10.alma.1.aarch64.rpm ef6da7a2352b6b7afaf5c6c56d77261788ebb92cf61c3beaecb6cc06e5b71c52
ppc64le osbuild-composer-core-101.5-2.el8_10.alma.1.ppc64le.rpm 49546a9a5ea27cd75194523ceb02bbb465ec8065c8c4bbb0c23ca824ece1c80c
ppc64le osbuild-composer-101.5-2.el8_10.alma.1.ppc64le.rpm 6e7fc2108fe92e0e635a2db625871abf522b5128a2eac4125c9e546cacf1ba8e
ppc64le osbuild-composer-worker-101.5-2.el8_10.alma.1.ppc64le.rpm 7e56185d5897f6f2f91e9f7b3b87ceb4c9dc9ed25ab0ae5f4da63f75e0fe309c
s390x osbuild-composer-worker-101.5-2.el8_10.alma.1.s390x.rpm 26e4e4a016524981be70f1ec5efcbfce91a3d296e6ca17ac9160f9e43b990e3c
s390x osbuild-composer-core-101.5-2.el8_10.alma.1.s390x.rpm 8836319fc61be0f855e3945c633383cfa084fcea4ec811e3ecd49e043eacddf5
s390x osbuild-composer-101.5-2.el8_10.alma.1.s390x.rpm acdd3469f653a2028fa59cf23b5e71cf6f27fadae0c8d257b70153fdef82a2b2
x86_64 osbuild-composer-101.5-2.el8_10.alma.1.x86_64.rpm 61216a7c4c3990bc8a01a3f4706498ab33446ddbf98cdce7c0bfc887cee4b32b
x86_64 osbuild-composer-worker-101.5-2.el8_10.alma.1.x86_64.rpm 63e628c64e53b0a9c047159ff98fe6878b667a8dbd7c20d50514826f55daf10c
x86_64 osbuild-composer-core-101.5-2.el8_10.alma.1.x86_64.rpm c4d463b49841b78d811a06b72cd7cb8ae050523305140d90a17b06c9d7a38212
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.