osbuild-composer-101.5-2.el8_10.ML.1

エラータID: AXSA:2026-1830:10

Release date: 
Tuesday, September 15, 2026 - 10:24
Subject: 
osbuild-composer-101.5-2.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

* golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355)
* golang: net/[http:](http:) net/[http:](http:) sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)
* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
* golang.org/x/net/idna: golang: net/[http:](http:) golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-45336
The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
CVE-2024-9355
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.
CVE-2026-33818
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
CVE-2026-39820
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
CVE-2026-56853
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
CVE-2026-56858
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
CVE-2026-56859
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
CVE-2026-56862
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. osbuild-composer-101.5-2.el8_10.ML.1.src.rpm
    MD5: 7e1bc46bf8904ff6cbb6bf1498b92346
    SHA-256: aeb372a52f369980ff65f42ef0c789ad84b5f91ad1653866d02634de4f48aee5
    Size: 129.63 MB

Asianux Server 8 for x86_64
  1. osbuild-composer-101.5-2.el8_10.ML.1.x86_64.rpm
    MD5: d66dd40d4897e5cccb3dc9a75c880b5d
    SHA-256: 0f262a7a2dcc1018e893b9c1da21a98373578d9649dd3cf0f27b7b21542605ff
    Size: 24.49 kB
  2. osbuild-composer-core-101.5-2.el8_10.ML.1.x86_64.rpm
    MD5: ef0ba856ea0b3105c94e247f43d65e91
    SHA-256: a88bd11f780d067774e8b761389338377a2437012d5b602151301a31bf623063
    Size: 11.32 MB
  3. osbuild-composer-worker-101.5-2.el8_10.ML.1.x86_64.rpm
    MD5: 54767833d2718ab320b714c2b483b0a6
    SHA-256: fcf34404e36b6cd081610b241e7ff1ec9d6bd72379fbec3838af5ec9902d6dcf
    Size: 20.11 MB