osbuild-composer-101.5-3.el8_10.ML.1

エラータID: AXSA:2026-1846:11

Release date: 
Wednesday, September 16, 2026 - 16:54
Subject: 
osbuild-composer-101.5-3.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

* crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-22866
Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVE-2026-41178
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.
CVE-2026-42499
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-42504
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVE-2026-55677
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. osbuild-composer-101.5-3.el8_10.ML.1.src.rpm
    MD5: edd3614783fb641f16903e6416783d66
    SHA-256: 2bb7ebd42b9ad7c0ed005a3d8c005fd4462ba1a3c51df0e9d98d49a6e7bbfd21
    Size: 129.86 MB

Asianux Server 8 for x86_64
  1. osbuild-composer-101.5-3.el8_10.ML.1.x86_64.rpm
    MD5: f0759eaaecff28569d24450400fe3629
    SHA-256: 656db3046adf6d480f41635b1726a18a123979c89e803776284237c83c58dccd
    Size: 24.79 kB
  2. osbuild-composer-core-101.5-3.el8_10.ML.1.x86_64.rpm
    MD5: 6f951d82d9038bde63b06c25017a3b30
    SHA-256: b745e9a16491bcfe35896db0bc5ab64afa3ed21296c7316a95d8eb7d010a81fc
    Size: 11.36 MB
  3. osbuild-composer-worker-101.5-3.el8_10.ML.1.x86_64.rpm
    MD5: c99aedbc80dd6e5898d91b40d642b92f
    SHA-256: 01f46ec9cb7012f2631fc949c51ed635c4def1136b73fe3f4d7fd89c60d02240
    Size: 20.13 MB