Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:18714 - Security Advisory
Issued:
2025-10-21
Updated:
2025-10-21

RHSA-2025:18714 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Low: osbuild-composer security update from RHEL

Type/Severity

Security Advisory: Low

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat In-Vehicle-OS version 1.0.0.

Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Please note as this is RHIVOS clone of RHEL advisory, see JIRA issues attached in References section. A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat In-Vehicle-OS version 1.0.0 Release Notes linked from the References section. Please note that Release Notes are available for subscribers only.

Solution

To update your implementation of Red Hat In-Vehicle Operating System,contact Red Hat Support: https://access.redhat.com/support.

Affected Products

  • Red Hat In-Vehicle Operating System Core 1 x86_64
  • Red Hat In-Vehicle Operating System Core 1 aarch64

Fixes

(none)

CVEs

(none)

References

  • https://access.redhat.com/security/updates/classification/#low
  • https://issues.redhat.com/browse/RHEL-84642
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat In-Vehicle Operating System Core 1

SRPM
osbuild-composer-132.2-1.el9_6.src.rpm SHA-256: 3c3c8e642b43596de779727fe1f785653942e55cfad050d202cf697842fe0944
x86_64
osbuild-composer-132.2-1.el9_6.x86_64.rpm SHA-256: 4bb0943cc6ccefa1f550b4c8b6d97497c9f9f76638129c91093f43cf1d135898
osbuild-composer-132.2-1.el9_6.x86_64.rpm SHA-256: 4bb0943cc6ccefa1f550b4c8b6d97497c9f9f76638129c91093f43cf1d135898
osbuild-composer-core-132.2-1.el9_6.x86_64.rpm SHA-256: 76b3c1369e995a7d046d1a83beb63b41f31e7035f824a06861779d684ff043d9
osbuild-composer-core-132.2-1.el9_6.x86_64.rpm SHA-256: 76b3c1369e995a7d046d1a83beb63b41f31e7035f824a06861779d684ff043d9
osbuild-composer-core-debuginfo-132.2-1.el9_6.x86_64.rpm SHA-256: d874a23a442c8ecd8cd28d77b3fd3e1312046f4149e2f3cb4174eb9888303e0d
osbuild-composer-core-debuginfo-132.2-1.el9_6.x86_64.rpm SHA-256: d874a23a442c8ecd8cd28d77b3fd3e1312046f4149e2f3cb4174eb9888303e0d
osbuild-composer-debuginfo-132.2-1.el9_6.x86_64.rpm SHA-256: 587ae4383436c7e32cd32daba56a4b1826db32f8aafcd4386853aebe80879cb8
osbuild-composer-debuginfo-132.2-1.el9_6.x86_64.rpm SHA-256: 587ae4383436c7e32cd32daba56a4b1826db32f8aafcd4386853aebe80879cb8
osbuild-composer-debugsource-132.2-1.el9_6.x86_64.rpm SHA-256: 8568f0686d9cc6dd8918ea5a544a3670631a4bc5140071e3d042ec669381b9bd
osbuild-composer-debugsource-132.2-1.el9_6.x86_64.rpm SHA-256: 8568f0686d9cc6dd8918ea5a544a3670631a4bc5140071e3d042ec669381b9bd
osbuild-composer-tests-debuginfo-132.2-1.el9_6.x86_64.rpm SHA-256: 5a01d0275fa455fa686a9c57c932af097163f5b0d882fc8e128e89cf06062b21
osbuild-composer-tests-debuginfo-132.2-1.el9_6.x86_64.rpm SHA-256: 5a01d0275fa455fa686a9c57c932af097163f5b0d882fc8e128e89cf06062b21
osbuild-composer-worker-132.2-1.el9_6.x86_64.rpm SHA-256: c8dd72ef651193e8adbac89f4327d96caff31585078236b9793edcb73f78f436
osbuild-composer-worker-132.2-1.el9_6.x86_64.rpm SHA-256: c8dd72ef651193e8adbac89f4327d96caff31585078236b9793edcb73f78f436
osbuild-composer-worker-debuginfo-132.2-1.el9_6.x86_64.rpm SHA-256: f93b84e56d30c001b623b0186792f2cd81c814a940dc03535f0409efce3ce0f9
osbuild-composer-worker-debuginfo-132.2-1.el9_6.x86_64.rpm SHA-256: f93b84e56d30c001b623b0186792f2cd81c814a940dc03535f0409efce3ce0f9
aarch64
osbuild-composer-132.2-1.el9_6.aarch64.rpm SHA-256: f5969a4c28d82a54de0a74a1c1a667032855994174b69e9df94c99d2aa09650e
osbuild-composer-132.2-1.el9_6.aarch64.rpm SHA-256: f5969a4c28d82a54de0a74a1c1a667032855994174b69e9df94c99d2aa09650e
osbuild-composer-core-132.2-1.el9_6.aarch64.rpm SHA-256: ea9d5e01354646d24006c6bbe906e962206b6a4e6081fe0fd0990a2273115ed3
osbuild-composer-core-132.2-1.el9_6.aarch64.rpm SHA-256: ea9d5e01354646d24006c6bbe906e962206b6a4e6081fe0fd0990a2273115ed3
osbuild-composer-core-debuginfo-132.2-1.el9_6.aarch64.rpm SHA-256: b8e92e13990e04c39f228fb4aaffc63a0b0592c8e3baeacab6230fc7d1de3526
osbuild-composer-core-debuginfo-132.2-1.el9_6.aarch64.rpm SHA-256: b8e92e13990e04c39f228fb4aaffc63a0b0592c8e3baeacab6230fc7d1de3526
osbuild-composer-debuginfo-132.2-1.el9_6.aarch64.rpm SHA-256: c2990b647c21a837a42ad6d8a3eac50cfe1c6da6be31481ed7f8f8cc7914f2c9
osbuild-composer-debuginfo-132.2-1.el9_6.aarch64.rpm SHA-256: c2990b647c21a837a42ad6d8a3eac50cfe1c6da6be31481ed7f8f8cc7914f2c9
osbuild-composer-debugsource-132.2-1.el9_6.aarch64.rpm SHA-256: a48a407694ec06b3d9b4fe71ed4bd6b819b0bbcbd7dead32e2a354f7c95f6a6e
osbuild-composer-debugsource-132.2-1.el9_6.aarch64.rpm SHA-256: a48a407694ec06b3d9b4fe71ed4bd6b819b0bbcbd7dead32e2a354f7c95f6a6e
osbuild-composer-tests-debuginfo-132.2-1.el9_6.aarch64.rpm SHA-256: d1305bf0309eae6332023358ca721fcdd8411c05a7ba90844802930f6f34a02b
osbuild-composer-tests-debuginfo-132.2-1.el9_6.aarch64.rpm SHA-256: d1305bf0309eae6332023358ca721fcdd8411c05a7ba90844802930f6f34a02b
osbuild-composer-worker-132.2-1.el9_6.aarch64.rpm SHA-256: d00afdd5dd3b73506f21f855f1c5e80117c818187f0c0692f2bcdd9f715bbda7
osbuild-composer-worker-132.2-1.el9_6.aarch64.rpm SHA-256: d00afdd5dd3b73506f21f855f1c5e80117c818187f0c0692f2bcdd9f715bbda7
osbuild-composer-worker-debuginfo-132.2-1.el9_6.aarch64.rpm SHA-256: 0cbf9a6d83a4564c132a9f6878e7e24b7dde7c402a566bf4c4ccc71c9854bf35
osbuild-composer-worker-debuginfo-132.2-1.el9_6.aarch64.rpm SHA-256: 0cbf9a6d83a4564c132a9f6878e7e24b7dde7c402a566bf4c4ccc71c9854bf35

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility