Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:47910: Important: osbuild-composer security update

This security update for osbuild-composer addresses multiple vulnerabilities in its underlying Go components, including a critical TLS session resumption flaw (CVE-2025-68121, CVSS 10.0) allowing incorrect certificate validation and several denial-of-service issues. The affected Go versions are below 1.24.13, 1.25.0 through 1.25.6, and 1.26.0 through 1.26.1. The fix requires applying the Red Hat update, which incorporates the patched Go versions 1.24.13, 1.25.7, or 1.26.2.
Read Full Article →

Red Hat Product Errata RHSA-2026:47910 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:47910 - Security Advisory Overview Updated Packages Synopsis Important: osbuild-composer security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for osbuild-composer is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVEs CVE-2025-68121 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM osbuild-composer-101.3-4.el9_4.3.src.rpm SHA-256: 4899e836eda538502b23b8cdc5dfc74a7030a400209a4d974240786113aef9da x86_64 osbuild-composer-101.3-4.el9_4.3.x86_64.rpm SHA-256: 378732a3f2c631d43c8bbe52301e15d20784585a52bc6e368205f5fe91e5ef9d osbuild-composer-core-101.3-4.el9_4.3.x86_64.rpm SHA-256: 1be3befb388a651e528359a5525d212e637c0354870f759b0fa640f63bcf58f3 osbuild-composer-core-debuginfo-101.3-4.el9_4.3.x86_64.rpm SHA-256: ba5a47bc21b65103b630c7cd2b0f6ba552bf835afe716b9e60fa200f685209c9 osbuild-composer-debuginfo-101.3-4.el9_4.3.x86_64.rpm SHA-256: 9641d9113f089d51c07fd535b720bf71786b69d4be60dfdc4c50ae2244bb492d osbuild-composer-debugsource-101.3-4.el9_4.3.x86_64.rpm SHA-256: 8877d3cfcb848bb17e0130cca06123be0cc710a1c5051f8100c79724be860e34 osbuild-composer-tests-debuginfo-101.3-4.el9_4.3.x86_64.rpm SHA-256: 2499d84bc3e4dcc37f993b0c5d68700e45f639b591d02415fd76091998e65dd7 osbuild-composer-worker-101.3-4.el9_4.3.x86_64.rpm SHA-256: be9e60ce55c4e19df9e7c3a39664b4149f6fd54518af8a5b20af2bf701a1ef69 osbuild-composer-worker-debuginfo-101.3-4.el9_4.3.x86_64.rpm SHA-256: bdd68d6df691c8e7695193dd2ad3cbd73468287304555399ff567e2df0cd9e33 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM osbuild-composer-101.3-4.el9_4.3.src.rpm SHA-256: 4899e836eda538502b23b8cdc5dfc74a7030a400209a4d974240786113aef9da ppc64le osbuild-composer-101.3-4.el9_4.3.ppc64le.rpm SHA-256: f500a4eca168b153d0cb307c611bd9317719eaaa96a3d2b4d800a84caa1932cb osbuild-composer-core-101.3-4.el9_4.3.ppc64le.rpm SHA-256: 76591578275148f5bd8ba62b1de1c9ebfd45ef5762c5d57f333801f89bbaa4dd osbuild-composer-core-debuginfo-101.3-4.el9_4.3.ppc64le.rpm SHA-256: 903f9f742722cdc138531d68d1a39ce8366eda6fda2d102cf30e67fa1f98159d osbuild-composer-debuginfo-101.3-4.el9_4.3.ppc64le.rpm SHA-256: e7cdd3a1b0abbde016127441ee816f247e021cdc94f3759586ee6591a93d17d1 osbuild-composer-debugsource-101.3-4.el9_4.3.ppc64le.rpm SHA-256: 24dd485c4262159f775afdcde3093168175376806171080948db11dd7f2c5be9 osbuild-composer-tests-debuginfo-101.3-4.el9_4.3.ppc64le.rpm SHA-256: b96cf38244ff6934d180a275165c394640250c67f49772a1ca576e236142c7fd osbuild-composer-worker-101.3-4.el9_4.3.ppc64le.rpm SHA-256: 0f7c8c2ae71a20c90196f0b57de2fd1c3144593a4b3332a5020b493e4b768f04 osbuild-composer-worker-debuginfo-101.3-4.el9_4.3.ppc64le.rpm SHA-256: b535781374481af46748cbfb4f8e9309f9268f056cf4aeb1fa66b8d04a12a311 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM osbuild-composer-101.3-4.el9_4.3.src.rpm SHA-256: 4899e836eda538502b23b8cdc5dfc74a7030a400209a4d974240786113aef9da x86_64 osbuild-composer-101.3-4.el9_4.3.x86_64.rpm SHA-256: 378732a3f2c631d43c8bbe52301e15d20784585a52bc6e368205f5fe91e5ef9d osbuild-composer-core-101.3-4.el9_4.3.x86_64.rpm SHA-256: 1be3befb388a651e528359a5525d212e637c0354870f759b0fa640f63bcf58f3 osbuild-composer-core-debuginfo-101.3-4.el9_4.3.x86_64.rpm SHA-256: ba5a47bc21b65103b630c7cd2b0f6ba552bf835afe716b9e60fa200f685209c9 osbuild-composer-debuginfo-101.3-4.el9_4.3.x86_64.rpm SHA-256: 9641d9113f089d51c07fd535b720bf71786b69d4be60dfdc4c50ae2244bb492d osbuild-composer-debugsource-101.3-4.el9_4.3.x86_64.rpm SHA-256: 8877d3cfcb848bb17e0130cca06123be0cc710a1c5051f8100c79724be860e34 osbuild-composer-tests-debuginfo-101.3-4.el9_4.3.x86_64.rpm SHA-256: 2499d84bc3e4dcc37f993b0c5d68700e45f639b591d02415fd76091998e65dd7 osbuild-composer-worker-101.3-4.el9_4.3.x86_64.rpm SHA-256: be9e60ce55c4e19df9e7c3a39664b4149f6fd54518af8a5b20af2bf701a1ef69 osbuild-composer-worker-debuginfo-101.3-4.el9_4.3.x86_64.rpm SHA-256: bdd68d6df691c8e7695193dd2ad3cbd73468287304555399ff567e2df0cd9e33 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM osbuild-composer-101.3-4.el9_4.3.src.rpm SHA-256: 4899e836eda538502b23b8cdc5dfc74a7030a400209a4d974240786113aef9da aarch64 osbuild-composer-101.3-4.el9_4.3.aarch64.rpm SHA-256: a9c45fb6ec2cfaeb968222976da48c9ea02de839023a778e550ab1c94fff5e0a osbuild-composer-core-101.3-4.el9_4.3.aarch64.rpm SHA-256: 2651b25f5c98c0b772f2aac732e61d14cfaded6b1ceb8c5e5bc15ed46ce8c711 osbuild-composer-core-debuginfo-101.3-4.el9_4.3.aarch64.rpm SHA-256: 78620e98489a8b709aec423e90d81b1b03832c19dd36c73da7f10655f63252e4 osbuild-composer-debuginfo-101.3-4.el9_4.3.aarch64.rpm SHA-256: 84be4e6e2df63dbb7f49ce20ee67fef8e88eeeba65731b12c6d0043c439c1a5f osbuild-composer-debugsource-101.3-4.el9_4.3.aarch64.rpm SHA-256: f14d8cf13b23ce84e0ccac7dd82a52708698b6017ecc6e65677499d4bb542d52 osbuild-composer-tests-debuginfo-101.3-4.el9_4.3.aarch64.rpm SHA-256: 75a6ada901d4432eea0a09761629a4d1ec769fc40f9f94db6e7682102b99d4c9 osbuild-composer-worker-101.3-4.el9_4.3.aarch64.rpm SHA-256: dd9246317da8adce550013b1de16e011df3c80a4149a2a73367eecbe781892cf osbuild-composer-worker-debuginfo-101.3-4.el9_4.3.aarch64.rpm SHA-256: 1b5b45cd5ad35243d0e8f9281c46be9d4dca47949610e21159129095b8c734da Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM osbuild-composer-101.3-4.el9_4.3.src.rpm SHA-256: 4899e836eda538502b23b8cdc5dfc74a7030a400209a4d974240786113aef9da s390x osbuild-composer-101.3-4.el9_4.3.s390x.rpm SHA-256: 071ac18be52e2cd10a9288a4bd9e27ea68d7313ba718c577a823d6778ec687da osbuild-composer-core-101.3-4.el9_4.3.s390x.rpm SHA-256: 32c2090f53d5537ad03b3e170bd1a2cb31c6b2ba13666c2503658b15b11a4846 osbuild-composer-core-debuginfo-101.3-4.el9_4.3.s390x.rpm SHA-256: 02c6ffcee695f105ca9caae6d8846a2cb69b2a20a7cec0764b56e67fb99aaf95 osbuild-composer-debuginfo-101.3-4.el9_4.3.s390x.rpm SHA-256: 38f465d159b41832df46f4fdb269607879713bb8429cf83ffc164009dbaa3b83 osbuild-composer-debugsource-101.3-4.el9_4.3.s390x.rpm SHA-256: a21eafbb9eaa3225f9e5fdacf1f70b3df995a270edee6c1228e6bf79602914a6 osbuild-composer-tests-debuginfo-101.3-4.el9_4.3.s390x.rpm SHA-256: 42eacb9976492b6c1a86921eb21c3fa6fa929036f0a559e9526357ce867cf6bf osbuild-composer-worker-101.3-4.el9_4.3.s390x.rpm SHA-256: c264f7f682bfe989a5fff3eb5234fab2ddc6fb47f9ac74dce6be43e68eabe375 osbuild-composer-worker-debuginfo-101.3-4.el9_4.3.s390x.rpm SHA-256: e9de22a3ffea89790bcea171fd4c830968bcfabac3fb9fe93c40414cfdf7e79c Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM osbuild-composer-101.3-4.el9_4.3.src.rpm SHA-256: 4899e836eda538502b23b8cdc5dfc74a7030a400209a4d974240786113aef9da x86_64 osbuild-composer-101.3-4.el9_4.3.x86_64.rpm SHA-256: 378732a3f2c631d43c8bbe52301e15d20784585a52bc6e368205f5fe91e5ef9d osbuild-composer-core-101.3-4.el9_4.3.x86_64.rpm SHA-256: 1be3befb388a651e528359a5525d212e637c0354870f759b0

Share this article