ALSA-2025:7118

Source
https://errata.almalinux.org/9/ALSA-2025-7118.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2025:7118.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2025:7118
Related
Published
2025-05-13T00:00:00Z
Modified
2025-07-02T13:30:04Z
Summary
Important: osbuild and osbuild-composer security update
Details

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
  • go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158)
  • golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinuxRelease Notes linked from the References section.

References

Affected packages

AlmaLinux:9 / osbuild

Package

Name
osbuild
Purl
pkg:rpm/almalinux/osbuild

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
141-1.el9.alma.1

AlmaLinux:9 / osbuild-composer

Package

Name
osbuild-composer
Purl
pkg:rpm/almalinux/osbuild-composer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
132-1.el9.alma.1

AlmaLinux:9 / osbuild-composer-core

Package

Name
osbuild-composer-core
Purl
pkg:rpm/almalinux/osbuild-composer-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
132-1.el9.alma.1

AlmaLinux:9 / osbuild-composer-worker

Package

Name
osbuild-composer-worker
Purl
pkg:rpm/almalinux/osbuild-composer-worker

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
132-1.el9.alma.1

AlmaLinux:9 / osbuild-depsolve-dnf

Package

Name
osbuild-depsolve-dnf
Purl
pkg:rpm/almalinux/osbuild-depsolve-dnf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
141-1.el9.alma.1

AlmaLinux:9 / osbuild-luks2

Package

Name
osbuild-luks2
Purl
pkg:rpm/almalinux/osbuild-luks2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
141-1.el9.alma.1

AlmaLinux:9 / osbuild-lvm2

Package

Name
osbuild-lvm2
Purl
pkg:rpm/almalinux/osbuild-lvm2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
141-1.el9.alma.1

AlmaLinux:9 / osbuild-ostree

Package

Name
osbuild-ostree
Purl
pkg:rpm/almalinux/osbuild-ostree

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
141-1.el9.alma.1

AlmaLinux:9 / osbuild-selinux

Package

Name
osbuild-selinux
Purl
pkg:rpm/almalinux/osbuild-selinux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
141-1.el9.alma.1

AlmaLinux:9 / python3-osbuild

Package

Name
python3-osbuild
Purl
pkg:rpm/almalinux/python3-osbuild

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
141-1.el9.alma.1