[Apollo] Advisories Statistics light light Login

RLSA-2026:65886

Security Mirrored from RHSA-2026:65886
Issued at: 2026-09-10
Updated at: 2026-09-10

Advisory content derived from Red Hat RHSA-2026:65886, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: image-builder security update



Description

A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.

Security Fix(es):

* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)

* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)

* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)

* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)

* golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)

* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)

* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)

* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)

* net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)

* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)

* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)

* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2456333 2456339 2467809 2467820 2467822 2480756 2484204 2515815 2515820 2515827 2515838 2515839 2515840

CVEs

CVE-2026-32280 CVE-2026-32281 CVE-2026-33811 CVE-2026-33818 CVE-2026-39820 CVE-2026-39821 CVE-2026-42499 CVE-2026-42504 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862

Affected packages

Rocky Linux 9 aarch64 - AppStream

image-builder-0:52.1-1.el9_8.2.aarch64.rpm image-builder-0:52.1-1.el9_8.2.src.rpm image-builder-debuginfo-0:52.1-1.el9_8.2.aarch64.rpm image-builder-debugsource-0:52.1-1.el9_8.2.aarch64.rpm

Rocky Linux 9 ppc64le - AppStream

image-builder-0:52.1-1.el9_8.2.ppc64le.rpm image-builder-0:52.1-1.el9_8.2.src.rpm image-builder-debuginfo-0:52.1-1.el9_8.2.ppc64le.rpm image-builder-debugsource-0:52.1-1.el9_8.2.ppc64le.rpm

Rocky Linux 9 s390x - AppStream

image-builder-0:52.1-1.el9_8.2.s390x.rpm image-builder-0:52.1-1.el9_8.2.src.rpm image-builder-debuginfo-0:52.1-1.el9_8.2.s390x.rpm image-builder-debugsource-0:52.1-1.el9_8.2.s390x.rpm

Rocky Linux 9 x86_64 - AppStream

image-builder-0:52.1-1.el9_8.2.src.rpm image-builder-0:52.1-1.el9_8.2.x86_64.rpm image-builder-debuginfo-0:52.1-1.el9_8.2.x86_64.rpm image-builder-debugsource-0:52.1-1.el9_8.2.x86_64.rpm