Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Release image-builder-52.1-1.el10_2 ALSA-2026:22937

Open
#2,694 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Quiet
Tech stack
go
Domain
security

Research direction

The issue names image-builder-52.1-1.el10_2, its affected architectures, and the CVEs, but does not identify repository files or tests. Start by locating the image-builder packaging or release entry point and checking how security updates are represented. Done means the listed affected packages and architectures reflect the requested release update.

Written by the indexing model from the issue text.

Description

image-builder security update
Severity: Important
Description
A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.

Security Fix(es):

  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
  • crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)
  • crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)
  • net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
  • google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)
  • github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
  • golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
  • crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
image-builder-52.1-1.el10_2.x86_64
image-builder-52.1-1.el10_2.s390x
image-builder-52.1-1.el10_2.ppc64le
image-builder-52.1-1.el10_2.aarch64
image-builder-52.1-1.el10_2.x86_64_v2

Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AlmaLinux/updates

All issues in AlmaLinux/updates

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.