[CLSA-2026:1780993851] osbuild-composer: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-09 08:31:16 UTC
Description:
- CVE-2026-32286: pgproto3 v2 DataRow.Decode panic on negative msgSize - CVE-2026-34986: go-jose v2 KeyUnwrap panic on too-short encrypted_key
Updated packages:
  • osbuild-composer-76-2.el9_2.2.alma.tuxcare.els3.x86_64.rpm
    sha:f5350346111c01e236cdf7a0f7543f1e393f66a7cad2ba9b7d5ab4da97a0a280
  • osbuild-composer-core-76-2.el9_2.2.alma.tuxcare.els3.x86_64.rpm
    sha:028a21e29c6f729bada1f75e47509b87cd4438a971eea8d237cf78a0521c59f7
  • osbuild-composer-dnf-json-76-2.el9_2.2.alma.tuxcare.els3.x86_64.rpm
    sha:8cde08763daa2571fa66d033d0b9711ba33b0af088ed7dd836cf82c0776fea93
  • osbuild-composer-tests-76-2.el9_2.2.alma.tuxcare.els3.x86_64.rpm
    sha:a253d05d63fb461088ba6b13e09e7fcd044c3cd58e2454fefea762c42df0474d
  • osbuild-composer-worker-76-2.el9_2.2.alma.tuxcare.els3.x86_64.rpm
    sha:5be17291e6e6837df2465559a8fef69b948d078d81d534dfd5a51779a9c4338a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.