osbuild-composer-149-3.el9_7.ML.1
エラータID: AXSA:2026-132:01
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.
Security Fix(es):
* golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2025-58183
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
Update packages.
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
N/A
SRPMS
- osbuild-composer-149-3.el9_7.ML.1.src.rpm
MD5: 50deef3d6e82a14ccfc01d863fab4818
SHA-256: 0fe995985a7db5eecc29f69baeee7daf4bddb4e7131660349d3044cdfadaa7f2
Size: 22.79 MB
Asianux Server 9 for x86_64
- osbuild-composer-149-3.el9_7.ML.1.x86_64.rpm
MD5: 8a6618b388758c8bcda84fd14cb0015b
SHA-256: b27ae8e7819aece725d8454b30563e4cbf95d4797b15b3e7adb73dbdddca9ccc
Size: 21.69 kB - osbuild-composer-core-149-3.el9_7.ML.1.x86_64.rpm
MD5: ef2f5686c405ca8a0de009cc2f777914
SHA-256: 4620138690418a9211ccfd4fe13fb004cc995f33038d37842342d93941f0ebd7
Size: 14.88 MB - osbuild-composer-worker-149-3.el9_7.ML.1.x86_64.rpm
MD5: bf41933904ed9c5207132a6618bd6ff2
SHA-256: 2dc3c6e7dd12ef319956fd0d7852bdbc9cbd8ae06d54d462cd5369a42926885d
Size: 24.65 MB