Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:67148

Опубликовано: 15 сент. 2026
Источник: rocky
Оценка: Important

Описание

Important: osbuild-composer security update

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)

  • crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)

  • net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)

  • mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)

  • github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)

  • github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
osbuild-composeraarch643.el8_10.rocky.0.6osbuild-composer-101.5-3.el8_10.rocky.0.6.aarch64.rpm
osbuild-composer-coreaarch643.el8_10.rocky.0.6osbuild-composer-core-101.5-3.el8_10.rocky.0.6.aarch64.rpm
osbuild-composer-workeraarch643.el8_10.rocky.0.6osbuild-composer-worker-101.5-3.el8_10.rocky.0.6.aarch64.rpm
osbuild-composerx86_643.el8_10.rocky.0.6osbuild-composer-101.5-3.el8_10.rocky.0.6.x86_64.rpm
osbuild-composer-corex86_643.el8_10.rocky.0.6osbuild-composer-core-101.5-3.el8_10.rocky.0.6.x86_64.rpm
osbuild-composer-workerx86_643.el8_10.rocky.0.6osbuild-composer-worker-101.5-3.el8_10.rocky.0.6.x86_64.rpm

Показывать по

Связанные уязвимости

CVSS3: 4
ubuntu
больше 1 года назад

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 5.3
redhat
больше 1 года назад

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 4
nvd
больше 1 года назад

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 8.4
msrc
около 1 года назад

Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

CVSS3: 4
debian
больше 1 года назад

Due to the usage of a variable time instruction in the assembly implem ...