Synopsis
Important: image-builder security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for image-builder is now available for Red Hat Enterprise Linux 10.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.
Security Fix(es):
- crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
- crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
- crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
- golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
- mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 10 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 10 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x
-
Red Hat Enterprise Linux for Power, little endian 10 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le
-
Red Hat Enterprise Linux for ARM 64 10 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x
-
Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le
-
Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x
Fixes
-
BZ - 2456333
- CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
-
BZ - 2456335
- CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
-
BZ - 2456339
- CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
-
BZ - 2467809
- CVE-2026-42499 net/mail: golang: net/mail: Denial of Service via pathological email address parsing
-
BZ - 2467820
- CVE-2026-39820 net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
-
BZ - 2467822
- CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
-
BZ - 2480756
- CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
-
BZ - 2484204
- CVE-2026-42504 mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
-
BZ - 2515815
- CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
-
BZ - 2515820
- CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
-
BZ - 2515827
- CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
-
BZ - 2515838
- CVE-2026-56858 html/template: golang: Go html/template: Cross-Site Scripting via pathological input
-
BZ - 2515839
- CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
-
BZ - 2515840
- CVE-2026-56859 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 10
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| x86_64 |
|
image-builder-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: abd41d2c4d8150e2bd0abdc1f443d4fd8fbee8d0b325b1399d9839ae80e1009e |
|
image-builder-debuginfo-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: db4add02c6297d88df870517e9b9ef3ffd222a9116c57d0633b0ea2284ecc68a |
|
image-builder-debugsource-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: 7f27eb4729c91219083f5d0c768c32774aed9ae9d3cd8f16feee5a4938b502b4 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| x86_64 |
|
image-builder-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: abd41d2c4d8150e2bd0abdc1f443d4fd8fbee8d0b325b1399d9839ae80e1009e |
|
image-builder-debuginfo-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: db4add02c6297d88df870517e9b9ef3ffd222a9116c57d0633b0ea2284ecc68a |
|
image-builder-debugsource-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: 7f27eb4729c91219083f5d0c768c32774aed9ae9d3cd8f16feee5a4938b502b4 |
Red Hat Enterprise Linux for IBM z Systems 10
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| s390x |
|
image-builder-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: ad345902f5287296c9777676ace860290b52ea78761acf0f541fac017d2b396c |
|
image-builder-debuginfo-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: 6b271a143e84372cc5985fa509955626782fb505e2b23548ce7ca40f7b72c53a |
|
image-builder-debugsource-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: 24fa8233b33d58cd5134057e6d9b079feb70d759f65213a51a4d0e6ff35bff16 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| s390x |
|
image-builder-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: ad345902f5287296c9777676ace860290b52ea78761acf0f541fac017d2b396c |
|
image-builder-debuginfo-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: 6b271a143e84372cc5985fa509955626782fb505e2b23548ce7ca40f7b72c53a |
|
image-builder-debugsource-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: 24fa8233b33d58cd5134057e6d9b079feb70d759f65213a51a4d0e6ff35bff16 |
Red Hat Enterprise Linux for Power, little endian 10
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| ppc64le |
|
image-builder-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: fe9f7b872ef3f85c212abf672dacfc33c9eb268d14cc93f76b7c5c90b0fafdac |
|
image-builder-debuginfo-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: f4fa1170db5eb7c0db4951f668010b37da51e42a5ed08a4bd06ec04d86d52f3a |
|
image-builder-debugsource-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: 93cd5facc02fc6b6a8ab64b9dba556d71c71b63b91f8186c7d4f6b0756e9e4ba |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| ppc64le |
|
image-builder-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: fe9f7b872ef3f85c212abf672dacfc33c9eb268d14cc93f76b7c5c90b0fafdac |
|
image-builder-debuginfo-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: f4fa1170db5eb7c0db4951f668010b37da51e42a5ed08a4bd06ec04d86d52f3a |
|
image-builder-debugsource-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: 93cd5facc02fc6b6a8ab64b9dba556d71c71b63b91f8186c7d4f6b0756e9e4ba |
Red Hat Enterprise Linux for ARM 64 10
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| aarch64 |
|
image-builder-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: 566b97497ad2fb99cee9f4960f2daaf30d1127f9c29bc5b5378d241882b33740 |
|
image-builder-debuginfo-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: 24d7de5da2a179d4cf21282a6ac913cb67e53d61b0e1ad3aada6bf77538674b6 |
|
image-builder-debugsource-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: db75eb77d721d09a98b403abc01241b79ce184f2b14a3b34fd76b9fedf879850 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| aarch64 |
|
image-builder-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: 566b97497ad2fb99cee9f4960f2daaf30d1127f9c29bc5b5378d241882b33740 |
|
image-builder-debuginfo-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: 24d7de5da2a179d4cf21282a6ac913cb67e53d61b0e1ad3aada6bf77538674b6 |
|
image-builder-debugsource-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: db75eb77d721d09a98b403abc01241b79ce184f2b14a3b34fd76b9fedf879850 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| aarch64 |
|
image-builder-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: 566b97497ad2fb99cee9f4960f2daaf30d1127f9c29bc5b5378d241882b33740 |
|
image-builder-debuginfo-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: 24d7de5da2a179d4cf21282a6ac913cb67e53d61b0e1ad3aada6bf77538674b6 |
|
image-builder-debugsource-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: db75eb77d721d09a98b403abc01241b79ce184f2b14a3b34fd76b9fedf879850 |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| s390x |
|
image-builder-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: ad345902f5287296c9777676ace860290b52ea78761acf0f541fac017d2b396c |
|
image-builder-debuginfo-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: 6b271a143e84372cc5985fa509955626782fb505e2b23548ce7ca40f7b72c53a |
|
image-builder-debugsource-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: 24fa8233b33d58cd5134057e6d9b079feb70d759f65213a51a4d0e6ff35bff16 |
Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| ppc64le |
|
image-builder-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: fe9f7b872ef3f85c212abf672dacfc33c9eb268d14cc93f76b7c5c90b0fafdac |
|
image-builder-debuginfo-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: f4fa1170db5eb7c0db4951f668010b37da51e42a5ed08a4bd06ec04d86d52f3a |
|
image-builder-debugsource-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: 93cd5facc02fc6b6a8ab64b9dba556d71c71b63b91f8186c7d4f6b0756e9e4ba |
Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| x86_64 |
|
image-builder-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: abd41d2c4d8150e2bd0abdc1f443d4fd8fbee8d0b325b1399d9839ae80e1009e |
|
image-builder-debuginfo-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: db4add02c6297d88df870517e9b9ef3ffd222a9116c57d0633b0ea2284ecc68a |
|
image-builder-debugsource-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: 7f27eb4729c91219083f5d0c768c32774aed9ae9d3cd8f16feee5a4938b502b4 |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| x86_64 |
|
image-builder-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: abd41d2c4d8150e2bd0abdc1f443d4fd8fbee8d0b325b1399d9839ae80e1009e |
|
image-builder-debuginfo-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: db4add02c6297d88df870517e9b9ef3ffd222a9116c57d0633b0ea2284ecc68a |
|
image-builder-debugsource-52.1-1.el10_2.2.x86_64.rpm
|
SHA-256: 7f27eb4729c91219083f5d0c768c32774aed9ae9d3cd8f16feee5a4938b502b4 |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| aarch64 |
|
image-builder-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: 566b97497ad2fb99cee9f4960f2daaf30d1127f9c29bc5b5378d241882b33740 |
|
image-builder-debuginfo-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: 24d7de5da2a179d4cf21282a6ac913cb67e53d61b0e1ad3aada6bf77538674b6 |
|
image-builder-debugsource-52.1-1.el10_2.2.aarch64.rpm
|
SHA-256: db75eb77d721d09a98b403abc01241b79ce184f2b14a3b34fd76b9fedf879850 |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| ppc64le |
|
image-builder-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: fe9f7b872ef3f85c212abf672dacfc33c9eb268d14cc93f76b7c5c90b0fafdac |
|
image-builder-debuginfo-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: f4fa1170db5eb7c0db4951f668010b37da51e42a5ed08a4bd06ec04d86d52f3a |
|
image-builder-debugsource-52.1-1.el10_2.2.ppc64le.rpm
|
SHA-256: 93cd5facc02fc6b6a8ab64b9dba556d71c71b63b91f8186c7d4f6b0756e9e4ba |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2
| SRPM |
|
image-builder-52.1-1.el10_2.2.src.rpm
|
SHA-256: eaad6b49d4a8fbc7c4ef5c1547fdb28bc2fe70c6b6e028372e2cc1b8400e2f3f |
| s390x |
|
image-builder-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: ad345902f5287296c9777676ace860290b52ea78761acf0f541fac017d2b396c |
|
image-builder-debuginfo-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: 6b271a143e84372cc5985fa509955626782fb505e2b23548ce7ca40f7b72c53a |
|
image-builder-debugsource-52.1-1.el10_2.2.s390x.rpm
|
SHA-256: 24fa8233b33d58cd5134057e6d9b079feb70d759f65213a51a4d0e6ff35bff16 |