Release image-builder-52.1-1.el10_2 ALSA-2026:22937
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
The issue names image-builder-52.1-1.el10_2, its affected architectures, and the CVEs, but does not identify repository files or tests. Start by locating the image-builder packaging or release entry point and checking how security updates are represented. Done means the listed affected packages and architectures reflect the requested release update.
Written by the indexing model from the issue text.
Description
image-builder security update
Severity: Important
Description
A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.
Security Fix(es):
- golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
- crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)
- crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)
- net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
- google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)
- github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
- golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
- crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
image-builder-52.1-1.el10_2.x86_64
image-builder-52.1-1.el10_2.s390x
image-builder-52.1-1.el10_2.ppc64le
image-builder-52.1-1.el10_2.aarch64
image-builder-52.1-1.el10_2.x86_64_v2
- Dominant language
- No language data
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from AlmaLinux/updates
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
Difficulty 1/5 Under an hour Newbie friendliness 60/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
All issues in AlmaLinux/updates
Similar issues
-
opencode: an unanswered --version probe launches opencode 2 without per-session service isolationOpen
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
security-advisory
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
MinBZK/regelrecht#1686 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
doorkeeper-gem/doorkeeper-openid_connect#409 · 1 comment ·
-
agent-ready area:breg bug criticality:p3 triage:needs-implementation
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
registrystack/registry-stack#1941 ·
Maintainers usually reply within 1 day
-
v1 v2
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
modelcontextprotocol/python-sdk#3652 · 1 comment ·
Maintainers usually reply within 1 day