Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:7793 - Security Advisory
Issued:
2024-10-08
Updated:
2024-10-08

RHSA-2024:7793 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: buildah security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for buildah is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2310528 - CVE-2024-34156 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

CVEs

  • CVE-2024-34156

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
buildah-1.26.7-1.el9_0.1.src.rpm SHA-256: 0bbc4da2bb0d868f7cfe37db4bf30fa454656da21ac0137fb2c01c95e9c63fb0
ppc64le
buildah-1.26.7-1.el9_0.1.ppc64le.rpm SHA-256: 8464e2f15e4a82a495e17d47d2f93e9041c8886b09aa1b58b00f5a2511868620
buildah-debuginfo-1.26.7-1.el9_0.1.ppc64le.rpm SHA-256: 0c24238a19d667fa7b87acda3298efc5e11c15754d322294848750c32e9a72ad
buildah-debugsource-1.26.7-1.el9_0.1.ppc64le.rpm SHA-256: 111922feef11b49af25b3d0735d43a2301d884411d8aec7ca8cc118442c8c226
buildah-tests-1.26.7-1.el9_0.1.ppc64le.rpm SHA-256: 5a61d54d26f64e6970943832ce8fcc41193b535033edb120408732953bb10e02
buildah-tests-debuginfo-1.26.7-1.el9_0.1.ppc64le.rpm SHA-256: 73e368f6789bc00909624708aa6e95b6739fcbcf1e8a245384ff6ac8e6e8c379

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
buildah-1.26.7-1.el9_0.1.src.rpm SHA-256: 0bbc4da2bb0d868f7cfe37db4bf30fa454656da21ac0137fb2c01c95e9c63fb0
x86_64
buildah-1.26.7-1.el9_0.1.x86_64.rpm SHA-256: ab76e89d3ac84c9f29bf43897cbf63fd03a1da87a8d44746d38585072475ec72
buildah-debuginfo-1.26.7-1.el9_0.1.x86_64.rpm SHA-256: 4045ba6be1b07d3be206f1536c0bca8046a82b65d4f736655cd846662b5665f6
buildah-debugsource-1.26.7-1.el9_0.1.x86_64.rpm SHA-256: a799685eda8bf501cddc5aeb4267e8361271c7659c45275110fd5f68cfb77ba8
buildah-tests-1.26.7-1.el9_0.1.x86_64.rpm SHA-256: 14d42b62d1aeb74225efe165a0415043e0c996f5d3dc775160715bba6f982853
buildah-tests-debuginfo-1.26.7-1.el9_0.1.x86_64.rpm SHA-256: 6d2f240417058097ae3a5be2e516fb0de514b3dd07fe6c73cd034a8ddd88ddc8

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
buildah-1.26.7-1.el9_0.1.src.rpm SHA-256: 0bbc4da2bb0d868f7cfe37db4bf30fa454656da21ac0137fb2c01c95e9c63fb0
aarch64
buildah-1.26.7-1.el9_0.1.aarch64.rpm SHA-256: 653fc829e2cda737caf71ab3510922ec85102ee4674cb6081585e19e1574aa06
buildah-debuginfo-1.26.7-1.el9_0.1.aarch64.rpm SHA-256: 5fccd072080e2c038e253907a2c5dc24a2d0c0f7831fa89a6a474529bd9d0e85
buildah-debugsource-1.26.7-1.el9_0.1.aarch64.rpm SHA-256: 870bfd103d01af9ca35051c1e28a6adfd81f3defa6fc32d7bbce3b62b0b497b8
buildah-tests-1.26.7-1.el9_0.1.aarch64.rpm SHA-256: 449f0172a280bf5dd796a00fa72bcab8231ccc42aea5a874543a43479d810a97
buildah-tests-debuginfo-1.26.7-1.el9_0.1.aarch64.rpm SHA-256: 5e2b6e42e76ed2b45b197494505e66ca4c17f96afb107f88eccfe3e99e249f31

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
buildah-1.26.7-1.el9_0.1.src.rpm SHA-256: 0bbc4da2bb0d868f7cfe37db4bf30fa454656da21ac0137fb2c01c95e9c63fb0
s390x
buildah-1.26.7-1.el9_0.1.s390x.rpm SHA-256: 3981ac4dd649021e69a29d4070b92f346aec43c12be811ef19fadea0af288b54
buildah-debuginfo-1.26.7-1.el9_0.1.s390x.rpm SHA-256: 1734d24e0af82ca483d5f625e1017059930b43dfa9a0f56cd4e9a6e90f463dc2
buildah-debugsource-1.26.7-1.el9_0.1.s390x.rpm SHA-256: e6a42a88a3481ac0ca999bcf42012ab1d1973a0e97b29144288468fc7b98326d
buildah-tests-1.26.7-1.el9_0.1.s390x.rpm SHA-256: 2e5a8d91aa5c987a6daab9df0ddead984af62290744768eef7178c676609be75
buildah-tests-debuginfo-1.26.7-1.el9_0.1.s390x.rpm SHA-256: b2d2586ce506f6a5a23db7d0ab31be7b976f2d5ba8bafa3a2414d8413e9ba329

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility