osbuild-composer-101.4-2.el8_10.ML.1

エラータID: AXSA:2026-143:02

Release date: 
Thursday, February 5, 2026 - 13:39
Subject: 
osbuild-composer-101.4-2.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

* golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-58183
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. osbuild-composer-101.4-2.el8_10.ML.1.src.rpm
    MD5: 49d15386e0419503561eb6fe7673f1ab
    SHA-256: 125399f3dfba1132784a93fa91420c483d485fe673b844eb1a412e6ca3f975aa
    Size: 130.08 MB

Asianux Server 8 for x86_64
  1. osbuild-composer-101.4-2.el8_10.ML.1.x86_64.rpm
    MD5: a59ebdb91ca5666baab9403f6d4624c5
    SHA-256: 4d61cccdc3d4dda358a9d7f5c25ac3097ba439c86f8352f777c1d8c84be8cc73
    Size: 23.38 kB
  2. osbuild-composer-core-101.4-2.el8_10.ML.1.x86_64.rpm
    MD5: 4a3f77c355318329f0cbdae3480bcc5f
    SHA-256: 67e50a1e83d52c0ea38a0e6afa1ac41f74d4bfeffb72b86d56d27f6a7939e8e2
    Size: 10.98 MB
  3. osbuild-composer-worker-101.4-2.el8_10.ML.1.x86_64.rpm
    MD5: de7c3e8e118150a90996b5702d2732e4
    SHA-256: de5cb1d31a3c58cbf14c11add12851cd5ab5d0b9793f4e728472721da73ff101
    Size: 19.49 MB