RHSA-2026:65886: Important: image
Synopsis
Important: image-builder security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for image-builder is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
A local binary for building customized OS artifacts such as VM images and OSTree commits. Uses osbuild under the hood.
Security Fix(es):
- crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
- crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
- golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
- mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 9 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 9 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x
-
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le
-
Red Hat Enterprise Linux for ARM 64 9 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x
Fixes
-
BZ - 2456333
- CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
-
BZ - 2456339
- CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
-
BZ - 2467809
- CVE-2026-42499 net/mail: golang: net/mail: Denial of Service via pathological email address parsing
-
BZ - 2467820
- CVE-2026-39820 net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
-
BZ - 2467822
- CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
-
BZ - 2480756
- CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
-
BZ - 2484204
- CVE-2026-42504 mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
-
BZ - 2515815
- CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
-
BZ - 2515820
- CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
-
BZ - 2515827
- CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
-
BZ - 2515838
- CVE-2026-56858 html/template: golang: Go html/template: Cross-Site Scripting via pathological input
-
BZ - 2515839
- CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
-
BZ - 2515840
- CVE-2026-56859 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 9
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| x86_64 |
|
image-builder-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: ac77b5a19d24d61acb87b98935371b337343f8e8dc5a351b7b100e523609efcd |
|
image-builder-debuginfo-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: 2647810a60fad359e0ee8149f692568594f7fcae55200a61448c55cb41975ef8 |
|
image-builder-debugsource-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: 9cb53689e5a4622201ff9a4654792f632cd2a7c12d4e8fb8089460a5e53089f1 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| x86_64 |
|
image-builder-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: ac77b5a19d24d61acb87b98935371b337343f8e8dc5a351b7b100e523609efcd |
|
image-builder-debuginfo-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: 2647810a60fad359e0ee8149f692568594f7fcae55200a61448c55cb41975ef8 |
|
image-builder-debugsource-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: 9cb53689e5a4622201ff9a4654792f632cd2a7c12d4e8fb8089460a5e53089f1 |
Red Hat Enterprise Linux for IBM z Systems 9
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| s390x |
|
image-builder-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: 42fd9f651807843d58ece6bf6ce992c5eaa9f75df2bee3b6464d4f06c2f662cc |
|
image-builder-debuginfo-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: 3b6c83896aa904bce80661269d01a7da98fb3a7febac95b3ee49363446c19ee6 |
|
image-builder-debugsource-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: a0db01aeaabedcbece9169c087867ccec7cecb5ca2572e637b2ce2abcb16a3fe |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| s390x |
|
image-builder-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: 42fd9f651807843d58ece6bf6ce992c5eaa9f75df2bee3b6464d4f06c2f662cc |
|
image-builder-debuginfo-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: 3b6c83896aa904bce80661269d01a7da98fb3a7febac95b3ee49363446c19ee6 |
|
image-builder-debugsource-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: a0db01aeaabedcbece9169c087867ccec7cecb5ca2572e637b2ce2abcb16a3fe |
Red Hat Enterprise Linux for Power, little endian 9
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| ppc64le |
|
image-builder-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 55341756a752c671ae9f9b8b5b94d75afe1478e224cce241cea0495099b7caed |
|
image-builder-debuginfo-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 9469a13b900778bbc499d92bdfd5a9e66cac5287d40f2052ddb400c08cc48e67 |
|
image-builder-debugsource-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 67e158970a30035b8f782b08d05799e0527e2c12d9d661b3c2d55a31603f2053 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| ppc64le |
|
image-builder-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 55341756a752c671ae9f9b8b5b94d75afe1478e224cce241cea0495099b7caed |
|
image-builder-debuginfo-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 9469a13b900778bbc499d92bdfd5a9e66cac5287d40f2052ddb400c08cc48e67 |
|
image-builder-debugsource-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 67e158970a30035b8f782b08d05799e0527e2c12d9d661b3c2d55a31603f2053 |
Red Hat Enterprise Linux for ARM 64 9
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| aarch64 |
|
image-builder-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: 59d6b12086284142bf80524b11647079812518c6328b3b9ddb7574c7438f496b |
|
image-builder-debuginfo-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: ed3ef244e507f36c79e3a51d9296e4de17e4e5bc364da275a65ea3867df6b0a1 |
|
image-builder-debugsource-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: 109c67ba38f1a2991451bec014b9380209239642911e09f817692ac1cc573d31 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| aarch64 |
|
image-builder-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: 59d6b12086284142bf80524b11647079812518c6328b3b9ddb7574c7438f496b |
|
image-builder-debuginfo-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: ed3ef244e507f36c79e3a51d9296e4de17e4e5bc364da275a65ea3867df6b0a1 |
|
image-builder-debugsource-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: 109c67ba38f1a2991451bec014b9380209239642911e09f817692ac1cc573d31 |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| ppc64le |
|
image-builder-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 55341756a752c671ae9f9b8b5b94d75afe1478e224cce241cea0495099b7caed |
|
image-builder-debuginfo-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 9469a13b900778bbc499d92bdfd5a9e66cac5287d40f2052ddb400c08cc48e67 |
|
image-builder-debugsource-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 67e158970a30035b8f782b08d05799e0527e2c12d9d661b3c2d55a31603f2053 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| x86_64 |
|
image-builder-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: ac77b5a19d24d61acb87b98935371b337343f8e8dc5a351b7b100e523609efcd |
|
image-builder-debuginfo-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: 2647810a60fad359e0ee8149f692568594f7fcae55200a61448c55cb41975ef8 |
|
image-builder-debugsource-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: 9cb53689e5a4622201ff9a4654792f632cd2a7c12d4e8fb8089460a5e53089f1 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| aarch64 |
|
image-builder-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: 59d6b12086284142bf80524b11647079812518c6328b3b9ddb7574c7438f496b |
|
image-builder-debuginfo-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: ed3ef244e507f36c79e3a51d9296e4de17e4e5bc364da275a65ea3867df6b0a1 |
|
image-builder-debugsource-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: 109c67ba38f1a2991451bec014b9380209239642911e09f817692ac1cc573d31 |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| s390x |
|
image-builder-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: 42fd9f651807843d58ece6bf6ce992c5eaa9f75df2bee3b6464d4f06c2f662cc |
|
image-builder-debuginfo-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: 3b6c83896aa904bce80661269d01a7da98fb3a7febac95b3ee49363446c19ee6 |
|
image-builder-debugsource-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: a0db01aeaabedcbece9169c087867ccec7cecb5ca2572e637b2ce2abcb16a3fe |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| x86_64 |
|
image-builder-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: ac77b5a19d24d61acb87b98935371b337343f8e8dc5a351b7b100e523609efcd |
|
image-builder-debuginfo-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: 2647810a60fad359e0ee8149f692568594f7fcae55200a61448c55cb41975ef8 |
|
image-builder-debugsource-52.1-1.el9_8.2.x86_64.rpm
|
SHA-256: 9cb53689e5a4622201ff9a4654792f632cd2a7c12d4e8fb8089460a5e53089f1 |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| aarch64 |
|
image-builder-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: 59d6b12086284142bf80524b11647079812518c6328b3b9ddb7574c7438f496b |
|
image-builder-debuginfo-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: ed3ef244e507f36c79e3a51d9296e4de17e4e5bc364da275a65ea3867df6b0a1 |
|
image-builder-debugsource-52.1-1.el9_8.2.aarch64.rpm
|
SHA-256: 109c67ba38f1a2991451bec014b9380209239642911e09f817692ac1cc573d31 |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| ppc64le |
|
image-builder-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 55341756a752c671ae9f9b8b5b94d75afe1478e224cce241cea0495099b7caed |
|
image-builder-debuginfo-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 9469a13b900778bbc499d92bdfd5a9e66cac5287d40f2052ddb400c08cc48e67 |
|
image-builder-debugsource-52.1-1.el9_8.2.ppc64le.rpm
|
SHA-256: 67e158970a30035b8f782b08d05799e0527e2c12d9d661b3c2d55a31603f2053 |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8
| SRPM |
|
image-builder-52.1-1.el9_8.2.src.rpm
|
SHA-256: 5649652e3067019336a4a041c9086314cb0b1a07a17da0fc18ab2d45efd532d3 |
| s390x |
|
image-builder-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: 42fd9f651807843d58ece6bf6ce992c5eaa9f75df2bee3b6464d4f06c2f662cc |
|
image-builder-debuginfo-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: 3b6c83896aa904bce80661269d01a7da98fb3a7febac95b3ee49363446c19ee6 |
|
image-builder-debugsource-52.1-1.el9_8.2.s390x.rpm
|
SHA-256: a0db01aeaabedcbece9169c087867ccec7cecb5ca2572e637b2ce2abcb16a3fe |
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.