[ALSA-2026:65153] Important: osbuild-composer security update
Type:
security
Severity:
important
Release date:
2026-09-15
Description:
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * golang.org/x/net/idna: golang: net/[http:](http:) golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 osbuild-composer-worker-165.1-4.el9_8.1.alma.1.aarch64.rpm 6e4ac014f3ab6fc6b364597aba546cb50633d7c46b93acaa3e8eee0fa62bbeb9
aarch64 osbuild-composer-core-165.1-4.el9_8.1.alma.1.aarch64.rpm b3fa6beae057500cdb5d79e918794d0752ba177dc627e13ca824a79c35a4049e
aarch64 osbuild-composer-165.1-4.el9_8.1.alma.1.aarch64.rpm e7cea77b95751891ee2496b85dfc8ecb3abcf232933f1bbf937bc40edc478c40
ppc64le osbuild-composer-165.1-4.el9_8.1.alma.1.ppc64le.rpm a734069614e371ce3a4c350a6df2bfd85f26d541cd985414db9c98e9287cfdb3
ppc64le osbuild-composer-worker-165.1-4.el9_8.1.alma.1.ppc64le.rpm c44d56a1eb3e249ead193459db44f3d66ba0fd903247040a59c195e05839a0d1
ppc64le osbuild-composer-core-165.1-4.el9_8.1.alma.1.ppc64le.rpm cdccdba92494f2cbe00bf808f466e29cac44f30a6391b21014de37396e087c58
s390x osbuild-composer-worker-165.1-4.el9_8.1.alma.1.s390x.rpm 6deb4e540d9a2d9429c90715284366f33f5221d66bd91139b50111d6937d74c7
s390x osbuild-composer-165.1-4.el9_8.1.alma.1.s390x.rpm 8d369898257ab1e11e080a875b7f72aa5b0e22077e54c6843dbd112eb030b4a3
s390x osbuild-composer-core-165.1-4.el9_8.1.alma.1.s390x.rpm 9c1815c04a60baf5aea3e89218fe0d2f5cea06cfa3cfe6196aebc0fce8d53194
x86_64 osbuild-composer-165.1-4.el9_8.1.alma.1.x86_64.rpm 38b528875dff86cff57f30915d52df540d9b56eb387047471ef8370b9564d95d
x86_64 osbuild-composer-core-165.1-4.el9_8.1.alma.1.x86_64.rpm 4a57e45060c0ad49d9cd47a66bda221238ca517a9aecd4d9396f3335f31d518c
x86_64 osbuild-composer-worker-165.1-4.el9_8.1.alma.1.x86_64.rpm 7af3e45a941d34910441b6605cef17ecbe118e2e1f050c8dd97f857e4e527df4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.