First published: Tue Nov 08 2022(Updated: )
Image Builder is a service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood.<br>Security Fix(es):<br><li> golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cockpit-composer | <41-1.el8 | 41-1.el8 |
redhat/osbuild | <65-1.el8 | 65-1.el8 |
redhat/osbuild-composer | <62-1.el8 | 62-1.el8 |
redhat/weldr-client | <35.5-4.el8 | 35.5-4.el8 |
redhat/cockpit-composer | <41-1.el8 | 41-1.el8 |
redhat/osbuild | <65-1.el8 | 65-1.el8 |
redhat/osbuild-composer | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-core | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-core-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-debugsource | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-dnf-json | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-tests-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-worker | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-worker-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-luks2 | <65-1.el8 | 65-1.el8 |
redhat/osbuild-lvm2 | <65-1.el8 | 65-1.el8 |
redhat/osbuild-ostree | <65-1.el8 | 65-1.el8 |
redhat/osbuild-selinux | <65-1.el8 | 65-1.el8 |
redhat/python3-osbuild | <65-1.el8 | 65-1.el8 |
redhat/weldr-client | <35.5-4.el8 | 35.5-4.el8 |
redhat/weldr-client-debuginfo | <35.5-4.el8 | 35.5-4.el8 |
redhat/weldr-client-debugsource | <35.5-4.el8 | 35.5-4.el8 |
redhat/weldr-client-tests-debuginfo | <35.5-4.el8 | 35.5-4.el8 |
redhat/osbuild-composer-core | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-core-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-debugsource | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-dnf-json | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-tests-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-worker | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-worker-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/weldr-client-debuginfo | <35.5-4.el8 | 35.5-4.el8 |
redhat/weldr-client-debugsource | <35.5-4.el8 | 35.5-4.el8 |
redhat/weldr-client-tests-debuginfo | <35.5-4.el8 | 35.5-4.el8 |
redhat/osbuild-composer | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-core | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-core-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-debugsource | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-dnf-json | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-tests-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-worker | <62-1.el8 | 62-1.el8 |
redhat/osbuild-composer-worker-debuginfo | <62-1.el8 | 62-1.el8 |
redhat/weldr-client | <35.5-4.el8 | 35.5-4.el8 |
redhat/weldr-client-debuginfo | <35.5-4.el8 | 35.5-4.el8 |
redhat/weldr-client-debugsource | <35.5-4.el8 | 35.5-4.el8 |
redhat/weldr-client-tests-debuginfo | <35.5-4.el8 | 35.5-4.el8 |
redhat/osbuild-composer | <62-1.el8.aa | 62-1.el8.aa |
redhat/osbuild-composer-core | <62-1.el8.aa | 62-1.el8.aa |
redhat/osbuild-composer-core-debuginfo | <62-1.el8.aa | 62-1.el8.aa |
redhat/osbuild-composer-debuginfo | <62-1.el8.aa | 62-1.el8.aa |
redhat/osbuild-composer-debugsource | <62-1.el8.aa | 62-1.el8.aa |
redhat/osbuild-composer-dnf-json | <62-1.el8.aa | 62-1.el8.aa |
redhat/osbuild-composer-tests-debuginfo | <62-1.el8.aa | 62-1.el8.aa |
redhat/osbuild-composer-worker | <62-1.el8.aa | 62-1.el8.aa |
redhat/osbuild-composer-worker-debuginfo | <62-1.el8.aa | 62-1.el8.aa |
redhat/weldr-client | <35.5-4.el8.aa | 35.5-4.el8.aa |
redhat/weldr-client-debuginfo | <35.5-4.el8.aa | 35.5-4.el8.aa |
redhat/weldr-client-debugsource | <35.5-4.el8.aa | 35.5-4.el8.aa |
redhat/weldr-client-tests-debuginfo | <35.5-4.el8.aa | 35.5-4.el8.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.