Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Release image-builder-52.1-2.el10_2 ALSA-2026:67139

Open
#3,527 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Active
Tech stack
go
Domain
devops, security

Research direction

Start with the affected image-builder packages and their osbuild context, then review the four CVEs listed in the issue. No source files or tests are named, so trace the package update entry point and confirm the resulting builds cover all listed architectures. Done means the affected image-builder packages include fixes for the referenced security issues.

Written by the indexing model from the issue text.

Description

image-builder security update
Severity: Important
Description
A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.

Security Fix(es):

  • golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
  • golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  • golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)
  • github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
image-builder-52.1-2.el10_2.x86_64
image-builder-52.1-2.el10_2.s390x
image-builder-52.1-2.el10_2.ppc64le
image-builder-52.1-2.el10_2.aarch64
image-builder-52.1-2.el10_2.x86_64_v2

Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AlmaLinux/updates

All issues in AlmaLinux/updates

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.