Red Hat Product Errata RHSA-2026:25252 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25252 - Security Advisory Overview Updated Packages Synopsis Important: buildah security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for buildah is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url BZ - 2455470 - CVE-2026-34986 github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVEs CVE-2025-61726 CVE-2025-61729 CVE-2025-68121 CVE-2026-25679 CVE-2026-34986 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 x86_64 buildah-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 1fe81746536ac0e77449f41a151332f51fc88caae097af09319be2745ff17b46 buildah-debuginfo-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 1fa288c75a13d1e0779bb0f9b35444b4ae67b3b126300f022a9b481521bda43e buildah-debugsource-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: d95d6e03c9c8cf273adc35fe6b05f308fa56151f83c6e86856adf87838f6702a buildah-tests-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 4c9c6cb487f5877ecdaf85614843423bed04de9b6ac126d782a585ae68aa22f7 buildah-tests-debuginfo-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 69c9bf2f15e057007c16c441504fc49a23dc1d3da6a9f553f633907478890168 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 ppc64le buildah-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: 9f40be3f8f2f93276937925ad43698cb2cc0ffc622006b833ff4887f6de8e3fe buildah-debuginfo-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: 3b12e19b639482da63096dec3ea52ce450e0f04760015757964b95d6831e77e9 buildah-debugsource-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: b5eb36ea8dab2a78723f88bd4ff288d1870d9c0e4e8229a0e289d2fcc3c9e49f buildah-tests-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: 9312ad3c773d9e012921501bb3b5e65e15729c999c479435b0ed1d45cb771022 buildah-tests-debuginfo-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: e874d9b4c80fb1543fe39afed4394acfa96e7a50d154f45b822522a96f911acb Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 x86_64 buildah-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 1fe81746536ac0e77449f41a151332f51fc88caae097af09319be2745ff17b46 buildah-debuginfo-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 1fa288c75a13d1e0779bb0f9b35444b4ae67b3b126300f022a9b481521bda43e buildah-debugsource-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: d95d6e03c9c8cf273adc35fe6b05f308fa56151f83c6e86856adf87838f6702a buildah-tests-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 4c9c6cb487f5877ecdaf85614843423bed04de9b6ac126d782a585ae68aa22f7 buildah-tests-debuginfo-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 69c9bf2f15e057007c16c441504fc49a23dc1d3da6a9f553f633907478890168 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 aarch64 buildah-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: 7f2d2356410272f8ec2b5036cb1510bc4ce5a93b94c17ba8d907b1283dc1d8e3 buildah-debuginfo-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: aae8f36a29a956ad0d6173efeaea22e32a0c0f79c9b4c5d60e79c7f9e5e6626f buildah-debugsource-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: 4827166cefdbbc45154bfe1224c626329730b4f745b7b577e26c55d776b2e989 buildah-tests-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: e57332877f52fdedc92acb603525f17907b43f14614617111b97e27fc62ff920 buildah-tests-debuginfo-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: c8b8780f5dc5d7a942eae4f2a56e6c4b320460fdf7c49b512d017794d3186136 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 s390x buildah-1.29.7-1.el9_2.5.s390x.rpm SHA-256: c9d1015b1e769408dcea122cab790c303d88af65c4777da45034adf0a6a99df1 buildah-debuginfo-1.29.7-1.el9_2.5.s390x.rpm SHA-256: 2dda1ce5f1b25a1f47d53bfd58e2b3b55b11bd038d1b735c19f66836fa859e11 buildah-debugsource-1.29.7-1.el9_2.5.s390x.rpm SHA-256: 5c4a6d626e219ce509b65c67ca62f38dc84b9e33e8d9f7a169b75f1f8057843e buildah-tests-1.29.7-1.el9_2.5.s390x.rpm SHA-256: 59980ed6a0a77554fe990fb2ddeacaa2c8fd2639d8a8289fd1dc8fe89d55a769 buildah-tests-debuginfo-1.29.7-1.el9_2.5.s390x.rpm SHA-256: 7e399fd13fca0b001b1eff10540dd5e5877e18825ec5684118f9e4a320d59ee5 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 x86_64 buildah-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 1fe81746536ac0e77449f41a151332f51fc88caae097af09319be2745ff17b46 buildah-debuginfo-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 1fa288c75a13d1e0779bb0f9b35444b4ae67b3b126300f022a9b481521bda43e buildah-debugsource-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: d95d6e03c9c8cf273adc35fe6b05f308fa56151f83c6e86856adf87838f6702a buildah-tests-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 4c9c6cb487f5877ecdaf85614843423bed04de9b6ac126d782a585ae68aa22f7 buildah-tests-debuginfo-1.29.7-1.el9_2.5.x86_64.rpm SHA-256: 69c9bf2f15e057007c16c441504fc49a23dc1d3da6a9f553f633907478890168 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 aarch64 buildah-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: 7f2d2356410272f8ec2b5036cb1510bc4ce5a93b94c17ba8d907b1283dc1d8e3 buildah-debuginfo-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: aae8f36a29a956ad0d6173efeaea22e32a0c0f79c9b4c5d60e79c7f9e5e6626f buildah-debugsource-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: 4827166cefdbbc45154bfe1224c626329730b4f745b7b577e26c55d776b2e989 buildah-tests-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: e57332877f52fdedc92acb603525f17907b43f14614617111b97e27fc62ff920 buildah-tests-debuginfo-1.29.7-1.el9_2.5.aarch64.rpm SHA-256: c8b8780f5dc5d7a942eae4f2a56e6c4b320460fdf7c49b512d017794d3186136 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 ppc64le buildah-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: 9f40be3f8f2f93276937925ad43698cb2cc0ffc622006b833ff4887f6de8e3fe buildah-debuginfo-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: 3b12e19b639482da63096dec3ea52ce450e0f04760015757964b95d6831e77e9 buildah-debugsource-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: b5eb36ea8dab2a78723f88bd4ff288d1870d9c0e4e8229a0e289d2fcc3c9e49f buildah-tests-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: 9312ad3c773d9e012921501bb3b5e65e15729c999c479435b0ed1d45cb771022 buildah-tests-debuginfo-1.29.7-1.el9_2.5.ppc64le.rpm SHA-256: e874d9b4c80fb1543fe39afed4394acfa96e7a50d154f45b822522a96f911acb Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 SRPM buildah-1.29.7-1.el9_2.5.src.rpm SHA-256: 891ed2c83e1b0d437d52f2b639cfa8a4ffcb8abb0e40c785bb0790332ea9df57 s390x buildah-1.29.7-1.el9_2.5.s390x.rp
This security update for the buildah container tool addresses multiple vulnerabilities in its underlying Go components, including a critical TLS session resumption flaw (CVE-2025-68121, CVSS 10.0) that allows incorrect certificate validation, high-severity denial-of-service issues in crypto/x509 and net/url parsing, and a JWE parsing flaw in the go-jose library. The vulnerabilities affect buildah packages on Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, as they incorporate affected Go versions prior to 1.24.11, 1.24.12, 1.24.13, and 1.25.5-1.25.7. The fix is applied by updating the buildah package via the Red Hat provided errata.