osbuild-composer-101-2.el9_4.ML.1

エラータID: AXSA:2024-8870:04

Release date: 
Tuesday, October 1, 2024 - 16:49
Subject: 
osbuild-composer-101-2.el9_4.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

* encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-34156
Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. osbuild-composer-101-2.el9_4.ML.1.src.rpm
    MD5: 53778304666738d211b8410ab94bd1dc
    SHA-256: 3ca481a1c733aa1e5ae76ec2ee3932f74f74be64c62a9bc7810390a48d1e7c89
    Size: 130.09 MB

Asianux Server 9 for x86_64
  1. osbuild-composer-101-2.el9_4.ML.1.x86_64.rpm
    MD5: 8b18bd732dbf41b2cdd47aa8f2c02536
    SHA-256: 712b8b43e912053392432b68038e614693023dedffcee0dc36e17c67104e4a93
    Size: 20.84 kB
  2. osbuild-composer-core-101-2.el9_4.ML.1.x86_64.rpm
    MD5: 6676e29b480ea1c0e7e5ec35385f6c70
    SHA-256: 313752088d3d06b035d50faf815373c80667b3b36051f9e1d071afe24da1c7bb
    Size: 10.34 MB
  3. osbuild-composer-worker-101-2.el9_4.ML.1.x86_64.rpm
    MD5: d87a5e1abd893f2d007918952524a2c3
    SHA-256: a1771f92eb1f9c7098e17baf7d3486c5a0ac990c5ff3dc8adbbd5fd0dbdc7c1a
    Size: 17.00 MB