Release image-builder-52.1-2.el10_2 ALSA-2026:67139
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 35/100
Research direction
Start with the affected image-builder packages and their osbuild context, then review the four CVEs listed in the issue. No source files or tests are named, so trace the package update entry point and confirm the resulting builds cover all listed architectures. Done means the affected image-builder packages include fixes for the referenced security issues.
Written by the indexing model from the issue text.
Description
image-builder security update
Severity: Important
Description
A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.
Security Fix(es):
- golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
- golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
- golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)
- github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
image-builder-52.1-2.el10_2.x86_64
image-builder-52.1-2.el10_2.s390x
image-builder-52.1-2.el10_2.ppc64le
image-builder-52.1-2.el10_2.aarch64
image-builder-52.1-2.el10_2.x86_64_v2
- Dominant language
- No language data
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from AlmaLinux/updates
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
Difficulty 1/5 Under an hour Newbie friendliness 60/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
All issues in AlmaLinux/updates
Similar issues
-
agentic-workflows untriaged
Difficulty 1/5 Under an hour Newbie friendliness 65/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 91/100
-
automation code-quality cookie improvement quick-win task-mining
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
Maintainers usually reply within 1 day
-
[arch] gate_sync.sh: stale remote tmp files on install failure; overlapping cron runs unguardedOpenarch area:fleet priority:p3 severity:low track:hosted-product
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
enhancement
Difficulty 1/5 Under an hour Newbie friendliness 85/100
alunduil/alunduil-chezmoi#852 ·
Maintainers usually reply within 1 day