Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:21401 - Security Advisory
Issued:
2025-11-17
Updated:
2025-11-17

RHSA-2025:21401 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Critical: lasso security update

Type/Severity

Security Advisory: Critical

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for lasso is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, and Red Hat Enterprise Linux 8.6 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The lasso packages provide the Lasso library that implements the Liberty Alliance Single Sign-On standards, including the SAML and SAML2 specifications. It allows handling of the whole life-cycle of SAML-based federations and provides bindings for multiple languages.

Security Fix(es):

  • lasso: Type confusion in Entr'ouvert Lasso (CVE-2025-47151)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.6 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64

Fixes

  • BZ - 2412739 - CVE-2025-47151 lasso: Type confusion in Entr'ouvert Lasso

CVEs

  • CVE-2025-47151

References

  • https://access.redhat.com/security/updates/classification/#critical
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6

SRPM
lasso-2.6.0-12.el8_6.1.src.rpm SHA-256: 1ad2546cab11ad2f30ce1c9b5fce49626432674d46f9fdaa43a3327783ee8558
x86_64
java-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: e54838a8803a10115e037bce217496fd67e630f27b40b99119e3b9d2d51d3daa
java-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 9135f2b01677b458ae02c3a9bafa0ab6297d9d8802bc30fcf3c0400ebe92f774
lasso-2.6.0-12.el8_6.1.i686.rpm SHA-256: c72338b12b1fe815547519f6ea1e54f201521d81b7c9e98381052610bb14542d
lasso-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 65f61e649446fbfff8dd98c329f90c82a2ef2b5522b36945cd0043003a23b8d8
lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: d21f3431204eb1e86dfe25b12e5bfc66a3f005be119d55b78cebed4ee4b131d9
lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: c494aabbf00281ffd510b83fd3286c6e38af94e4dc318a89b54a6d2d1d99c4fa
lasso-debugsource-2.6.0-12.el8_6.1.i686.rpm SHA-256: 875eba1987d78fca2319cae7fef56566230c3aad85628a9924ac164604005742
lasso-debugsource-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: d1f7738c3577aa5ce8f30d4d89ccbd34499d2d0d70ad05b2d7ecce85961794d7
perl-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: ab6d5b61e02765b60c7acaed39a7dfc3026cbc01b56a86247cab71dae87f04d5
perl-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 46839772ed1f0daa17f4c7a98415b2a81a8aa90163c5efe5e97f1fff8f2e4d2f
python3-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: 9900f35261cb043324ffc6ea5544062671a4de6285e0ae56818705ffdc5268c6
python3-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 1e3f484555a45b34d588c28172ca5ef93193a8d0799d921e80ff7111e968ad6d

Red Hat Enterprise Linux Server - AUS 8.6

SRPM
lasso-2.6.0-12.el8_6.1.src.rpm SHA-256: 1ad2546cab11ad2f30ce1c9b5fce49626432674d46f9fdaa43a3327783ee8558
x86_64
java-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: e54838a8803a10115e037bce217496fd67e630f27b40b99119e3b9d2d51d3daa
java-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 9135f2b01677b458ae02c3a9bafa0ab6297d9d8802bc30fcf3c0400ebe92f774
lasso-2.6.0-12.el8_6.1.i686.rpm SHA-256: c72338b12b1fe815547519f6ea1e54f201521d81b7c9e98381052610bb14542d
lasso-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 65f61e649446fbfff8dd98c329f90c82a2ef2b5522b36945cd0043003a23b8d8
lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: d21f3431204eb1e86dfe25b12e5bfc66a3f005be119d55b78cebed4ee4b131d9
lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: c494aabbf00281ffd510b83fd3286c6e38af94e4dc318a89b54a6d2d1d99c4fa
lasso-debugsource-2.6.0-12.el8_6.1.i686.rpm SHA-256: 875eba1987d78fca2319cae7fef56566230c3aad85628a9924ac164604005742
lasso-debugsource-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: d1f7738c3577aa5ce8f30d4d89ccbd34499d2d0d70ad05b2d7ecce85961794d7
perl-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: ab6d5b61e02765b60c7acaed39a7dfc3026cbc01b56a86247cab71dae87f04d5
perl-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 46839772ed1f0daa17f4c7a98415b2a81a8aa90163c5efe5e97f1fff8f2e4d2f
python3-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: 9900f35261cb043324ffc6ea5544062671a4de6285e0ae56818705ffdc5268c6
python3-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 1e3f484555a45b34d588c28172ca5ef93193a8d0799d921e80ff7111e968ad6d

Red Hat Enterprise Linux Server - TUS 8.6

SRPM
lasso-2.6.0-12.el8_6.1.src.rpm SHA-256: 1ad2546cab11ad2f30ce1c9b5fce49626432674d46f9fdaa43a3327783ee8558
x86_64
java-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: e54838a8803a10115e037bce217496fd67e630f27b40b99119e3b9d2d51d3daa
java-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 9135f2b01677b458ae02c3a9bafa0ab6297d9d8802bc30fcf3c0400ebe92f774
lasso-2.6.0-12.el8_6.1.i686.rpm SHA-256: c72338b12b1fe815547519f6ea1e54f201521d81b7c9e98381052610bb14542d
lasso-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 65f61e649446fbfff8dd98c329f90c82a2ef2b5522b36945cd0043003a23b8d8
lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: d21f3431204eb1e86dfe25b12e5bfc66a3f005be119d55b78cebed4ee4b131d9
lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: c494aabbf00281ffd510b83fd3286c6e38af94e4dc318a89b54a6d2d1d99c4fa
lasso-debugsource-2.6.0-12.el8_6.1.i686.rpm SHA-256: 875eba1987d78fca2319cae7fef56566230c3aad85628a9924ac164604005742
lasso-debugsource-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: d1f7738c3577aa5ce8f30d4d89ccbd34499d2d0d70ad05b2d7ecce85961794d7
perl-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: ab6d5b61e02765b60c7acaed39a7dfc3026cbc01b56a86247cab71dae87f04d5
perl-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 46839772ed1f0daa17f4c7a98415b2a81a8aa90163c5efe5e97f1fff8f2e4d2f
python3-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: 9900f35261cb043324ffc6ea5544062671a4de6285e0ae56818705ffdc5268c6
python3-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 1e3f484555a45b34d588c28172ca5ef93193a8d0799d921e80ff7111e968ad6d

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6

SRPM
lasso-2.6.0-12.el8_6.1.src.rpm SHA-256: 1ad2546cab11ad2f30ce1c9b5fce49626432674d46f9fdaa43a3327783ee8558
ppc64le
java-lasso-debuginfo-2.6.0-12.el8_6.1.ppc64le.rpm SHA-256: 4348ee4b4fd5fde488a7c9a71e90cf6e76f297b37c50e0508e2332bac0b1c917
lasso-2.6.0-12.el8_6.1.ppc64le.rpm SHA-256: 0cf1ac1fdf0f0a68d5a25203c0cc3c4ffa6fb3a1af2842c9da99f6e8c3cbcf96
lasso-debuginfo-2.6.0-12.el8_6.1.ppc64le.rpm SHA-256: 38be9f50d56f8eee13b1002771ec1fdef8f216c966a0e001ab4e8dcbea73c340
lasso-debugsource-2.6.0-12.el8_6.1.ppc64le.rpm SHA-256: 9bc92ac45d2131da005abece4bbc0078c875893b225462e1ff2baa3861fb05a3
perl-lasso-debuginfo-2.6.0-12.el8_6.1.ppc64le.rpm SHA-256: 90873d23b63e7562082828be92f436f1cf2f1d3afc86944fb97ac7262eeacf07
python3-lasso-debuginfo-2.6.0-12.el8_6.1.ppc64le.rpm SHA-256: 633d8ed6e0af305442c58f21228e246d1bc42f8ba13850e999c5aecbfdc2d28c

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6

SRPM
lasso-2.6.0-12.el8_6.1.src.rpm SHA-256: 1ad2546cab11ad2f30ce1c9b5fce49626432674d46f9fdaa43a3327783ee8558
x86_64
java-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: e54838a8803a10115e037bce217496fd67e630f27b40b99119e3b9d2d51d3daa
java-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 9135f2b01677b458ae02c3a9bafa0ab6297d9d8802bc30fcf3c0400ebe92f774
lasso-2.6.0-12.el8_6.1.i686.rpm SHA-256: c72338b12b1fe815547519f6ea1e54f201521d81b7c9e98381052610bb14542d
lasso-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 65f61e649446fbfff8dd98c329f90c82a2ef2b5522b36945cd0043003a23b8d8
lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: d21f3431204eb1e86dfe25b12e5bfc66a3f005be119d55b78cebed4ee4b131d9
lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: c494aabbf00281ffd510b83fd3286c6e38af94e4dc318a89b54a6d2d1d99c4fa
lasso-debugsource-2.6.0-12.el8_6.1.i686.rpm SHA-256: 875eba1987d78fca2319cae7fef56566230c3aad85628a9924ac164604005742
lasso-debugsource-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: d1f7738c3577aa5ce8f30d4d89ccbd34499d2d0d70ad05b2d7ecce85961794d7
perl-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: ab6d5b61e02765b60c7acaed39a7dfc3026cbc01b56a86247cab71dae87f04d5
perl-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 46839772ed1f0daa17f4c7a98415b2a81a8aa90163c5efe5e97f1fff8f2e4d2f
python3-lasso-debuginfo-2.6.0-12.el8_6.1.i686.rpm SHA-256: 9900f35261cb043324ffc6ea5544062671a4de6285e0ae56818705ffdc5268c6
python3-lasso-debuginfo-2.6.0-12.el8_6.1.x86_64.rpm SHA-256: 1e3f484555a45b34d588c28172ca5ef93193a8d0799d921e80ff7111e968ad6d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility