Release image-builder-52.1-1.el10_2.2 ALSA-2026:65534
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
Research direction
No source file, test, or entry point is identified in the issue. Start by examining the repository's update and release workflow, then locate the image-builder package metadata and verify the listed affected versions and CVEs; done should mean the requested security update is correctly represented and validated.
Written by the indexing model from the issue text.
Description
image-builder security update
Severity: Important
Description
A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.
Security Fix(es):
- crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
- crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
- crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
- golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
- mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
image-builder-52.1-1.el10_2.2.x86_64
image-builder-52.1-1.el10_2.2.s390x
image-builder-52.1-1.el10_2.2.ppc64le
image-builder-52.1-1.el10_2.2.aarch64
image-builder-52.1-1.el10_2.2.x86_64_v2
- Dominant language
- No language data
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from AlmaLinux/updates
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
Difficulty 1/5 Under an hour Newbie friendliness 60/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
Difficulty 4/5 3-5 days Newbie friendliness 30/100
-
Difficulty 3/5 1-2 days Newbie friendliness 52/100
All issues in AlmaLinux/updates
Similar issues
-
status: waiting-for-triage type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
spring-projects/spring-security#19847 ·
Maintainers usually reply within 1 day
-
area:auth bug triage:confirmed
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Cotal-AI/Cotal#3414 · 1 comment ·
Maintainers usually reply within 1 day
-
architecture
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
DiegoMicali/MovieFlix#16 ·
-
area/auth area/billing comp/agent duplicate P2 provider/anthropic sweeper:risk-security-boundary type/bug
Difficulty 2/5 1-3 hours Newbie friendliness 63/100
NousResearch/hermes-agent#134897 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100