Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Release image-builder-52.1-1.el10_2.2 ALSA-2026:65534

Open
#3,478 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Active
Tech stack
go
Domain
security

Research direction

No source file, test, or entry point is identified in the issue. Start by examining the repository's update and release workflow, then locate the image-builder package metadata and verify the listed affected versions and CVEs; done should mean the requested security update is correctly represented and validated.

Written by the indexing model from the issue text.

Description

image-builder security update
Severity: Important
Description
A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.

Security Fix(es):

  • crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
  • crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
  • crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
  • net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
  • net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
  • net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  • golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
  • mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
  • encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
  • net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
  • net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
  • html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
  • crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
  • encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
image-builder-52.1-1.el10_2.2.x86_64
image-builder-52.1-1.el10_2.2.s390x
image-builder-52.1-1.el10_2.2.ppc64le
image-builder-52.1-1.el10_2.2.aarch64
image-builder-52.1-1.el10_2.2.x86_64_v2

Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AlmaLinux/updates

All issues in AlmaLinux/updates

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.