Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:52389: Important: osbuild-composer security update

This Important update for osbuild-composer addresses CVE-2026-25679 (CVSS 7.5 High), a vulnerability in the `net/url` library causing incorrect parsing of IPv6 host literals. The underlying Go language vulnerability affects Go versions prior to 1.25.8 and version 1.26.0. The fix is provided by updating the osbuild-composer packages to version 75-9.el8_8 for the specified RHEL 8.8 Extended Life Cycle and Update Services channels.
Read Full Article →

Red Hat Product Errata RHSA-2026:52389 - Security Advisory Issued: 2026-08-10 Updated: 2026-08-10 RHSA-2026:52389 - Security Advisory Overview Updated Packages Synopsis Important: osbuild-composer security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url CVEs CVE-2026-25679 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM osbuild-composer-75-9.el8_8.src.rpm SHA-256: dbde58e58d3caf3cab789bcbc88da8802b8cc06f1cf53a6e20ccab77f82f1318 x86_64 osbuild-composer-75-9.el8_8.x86_64.rpm SHA-256: a95c84343d936b25e5a15c00448c3de73aac46bcd290fcb0e087e85387d7681b osbuild-composer-core-75-9.el8_8.x86_64.rpm SHA-256: fb993267cbb3cbd860d68ced57e6d6b99d94c286e5f98b40e78d8140fe3e4783 osbuild-composer-core-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 7d2ffa5b592879970cedb1b887f81d65ca4b1bf9d96aafc63ec765e2c401c4c2 osbuild-composer-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 5533d9abe9a7b1c9d7358feec2d6d0bdfe94a77f7fd58667b707d41cfecaa58f osbuild-composer-debugsource-75-9.el8_8.x86_64.rpm SHA-256: da9f36cc3b7ccd149259c428d67c4eb7b18c2af8f5ce82a963d3011b06136426 osbuild-composer-dnf-json-75-9.el8_8.x86_64.rpm SHA-256: 1278d0ebc007ba5008d271c098b69d85f718e5f3f0876a72e80e42f216e8078c osbuild-composer-tests-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: d163c0e9db1d0a10f3790b81a0c83b9585358d78a57b5ba0c62855f820d4b5c6 osbuild-composer-worker-75-9.el8_8.x86_64.rpm SHA-256: 6326b1f2aaa4e34e4d4e7d07c1e747d780a5afd53a73a6420c6c37d433f703fb osbuild-composer-worker-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 8e193e04a8bdb844624119944e65b2e7d23ba5bc5eba409e24cc2171809d33b7 Red Hat Enterprise Linux Server - TUS 8.8 SRPM osbuild-composer-75-9.el8_8.src.rpm SHA-256: dbde58e58d3caf3cab789bcbc88da8802b8cc06f1cf53a6e20ccab77f82f1318 x86_64 osbuild-composer-75-9.el8_8.x86_64.rpm SHA-256: a95c84343d936b25e5a15c00448c3de73aac46bcd290fcb0e087e85387d7681b osbuild-composer-core-75-9.el8_8.x86_64.rpm SHA-256: fb993267cbb3cbd860d68ced57e6d6b99d94c286e5f98b40e78d8140fe3e4783 osbuild-composer-core-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 7d2ffa5b592879970cedb1b887f81d65ca4b1bf9d96aafc63ec765e2c401c4c2 osbuild-composer-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 5533d9abe9a7b1c9d7358feec2d6d0bdfe94a77f7fd58667b707d41cfecaa58f osbuild-composer-debugsource-75-9.el8_8.x86_64.rpm SHA-256: da9f36cc3b7ccd149259c428d67c4eb7b18c2af8f5ce82a963d3011b06136426 osbuild-composer-dnf-json-75-9.el8_8.x86_64.rpm SHA-256: 1278d0ebc007ba5008d271c098b69d85f718e5f3f0876a72e80e42f216e8078c osbuild-composer-tests-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: d163c0e9db1d0a10f3790b81a0c83b9585358d78a57b5ba0c62855f820d4b5c6 osbuild-composer-worker-75-9.el8_8.x86_64.rpm SHA-256: 6326b1f2aaa4e34e4d4e7d07c1e747d780a5afd53a73a6420c6c37d433f703fb osbuild-composer-worker-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 8e193e04a8bdb844624119944e65b2e7d23ba5bc5eba409e24cc2171809d33b7 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM osbuild-composer-75-9.el8_8.src.rpm SHA-256: dbde58e58d3caf3cab789bcbc88da8802b8cc06f1cf53a6e20ccab77f82f1318 ppc64le osbuild-composer-75-9.el8_8.ppc64le.rpm SHA-256: a22f34d3fc59ef8aa747544b91c4b1916dac1d35c94325f49776b8f8a096b739 osbuild-composer-core-75-9.el8_8.ppc64le.rpm SHA-256: 9e850548dd031cc86f0c71a1ba048447929e16735dfa0afe36c24e9daafbc164 osbuild-composer-core-debuginfo-75-9.el8_8.ppc64le.rpm SHA-256: 7bcd6555b8bbb8a687544f0f3fcb0f96f7af4c26b2fe7010ffc6f8bbb373913b osbuild-composer-debuginfo-75-9.el8_8.ppc64le.rpm SHA-256: c138ca5e322eb832119cea58586fd706f5098e85cb51583268dfa2b3b720a716 osbuild-composer-debugsource-75-9.el8_8.ppc64le.rpm SHA-256: 83601215df3f6c2f8e68f90c9607c0bc0f1b04a5c5e5f91d7c40436f443fb1a9 osbuild-composer-dnf-json-75-9.el8_8.ppc64le.rpm SHA-256: 3e094cd6c8a97259e949f024071036402553482e751d758c61272b920bd9be55 osbuild-composer-tests-debuginfo-75-9.el8_8.ppc64le.rpm SHA-256: 63b9c65324e793fa26ac74f24ded57549e35f0397d05cf8a7a2d0444e3a1334c osbuild-composer-worker-75-9.el8_8.ppc64le.rpm SHA-256: 081d7118696f84b3c384cbcc1adde01edcf910620adb583c5d7a52b32fd3d79d osbuild-composer-worker-debuginfo-75-9.el8_8.ppc64le.rpm SHA-256: 02b6858c9ff8ab7525d8662875cf8383058ff46a6aaf8a672c0c5bb1fe5d4574 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM osbuild-composer-75-9.el8_8.src.rpm SHA-256: dbde58e58d3caf3cab789bcbc88da8802b8cc06f1cf53a6e20ccab77f82f1318 x86_64 osbuild-composer-75-9.el8_8.x86_64.rpm SHA-256: a95c84343d936b25e5a15c00448c3de73aac46bcd290fcb0e087e85387d7681b osbuild-composer-core-75-9.el8_8.x86_64.rpm SHA-256: fb993267cbb3cbd860d68ced57e6d6b99d94c286e5f98b40e78d8140fe3e4783 osbuild-composer-core-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 7d2ffa5b592879970cedb1b887f81d65ca4b1bf9d96aafc63ec765e2c401c4c2 osbuild-composer-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 5533d9abe9a7b1c9d7358feec2d6d0bdfe94a77f7fd58667b707d41cfecaa58f osbuild-composer-debugsource-75-9.el8_8.x86_64.rpm SHA-256: da9f36cc3b7ccd149259c428d67c4eb7b18c2af8f5ce82a963d3011b06136426 osbuild-composer-dnf-json-75-9.el8_8.x86_64.rpm SHA-256: 1278d0ebc007ba5008d271c098b69d85f718e5f3f0876a72e80e42f216e8078c osbuild-composer-tests-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: d163c0e9db1d0a10f3790b81a0c83b9585358d78a57b5ba0c62855f820d4b5c6 osbuild-composer-worker-75-9.el8_8.x86_64.rpm SHA-256: 6326b1f2aaa4e34e4d4e7d07c1e747d780a5afd53a73a6420c6c37d433f703fb osbuild-composer-worker-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 8e193e04a8bdb844624119944e65b2e7d23ba5bc5eba409e24cc2171809d33b7 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article