[CLSA-2026:1776954912] osbuild-composer: Fix of CVE-2026-25679
Type:
security
Severity:
Important
Release date:
2026-04-23 19:49:51 UTC
Description:
- rebuild with newer golang 1.25.7-1.el9_6.tuxcare.els2 to fix CVE-2026-25679 (net/url: reject IPv6 literal not at start of host)
Updated packages:
  • osbuild-composer-132.2-3.el9_6.alma.1.tuxcare.els2.x86_64.rpm
    sha:f2188c0885d06187dcff161014d02ce1260caf8762e005a0c3e6a255ca782cc9
  • osbuild-composer-core-132.2-3.el9_6.alma.1.tuxcare.els2.x86_64.rpm
    sha:805d4d7f577227652991b56bc5f59b752cc2b7843aaa561fc6cb0210cb5319b8
  • osbuild-composer-tests-132.2-3.el9_6.alma.1.tuxcare.els2.x86_64.rpm
    sha:735edb126f6b262c508423426e5e345f8ed254b59e5f4943f8cbc34fc9b52db9
  • osbuild-composer-worker-132.2-3.el9_6.alma.1.tuxcare.els2.x86_64.rpm
    sha:c77c827697e15bfeb81ef813cbb0c76d174498d61947f5fadbd1202d2ff7ba12
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.