Lucene search

K
redhatRedHatRHSA-2022:7548
HistoryNov 08, 2022 - 6:22 a.m.

(RHSA-2022:7548) Low: Image Builder security, bug fix, and enhancement update

2022-11-0806:22:29
access.redhat.com
13
image builder
os artifacts
osbuild
golang
math/big
cve-2022-32189
denial of service
red hat enterprise linux 8.7.

0.002 Low

EPSS

Percentile

57.4%

Image Builder is a service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood.

Security Fix(es):

  • golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.