Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:21404 - Security Advisory
Issued:
2025-11-17
Updated:
2025-11-17

RHSA-2025:21404 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Critical: lasso security update

Type/Severity

Security Advisory: Critical

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for lasso is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The lasso packages provide the Lasso library that implements the Liberty Alliance Single Sign-On standards, including the SAML and SAML2 specifications. It allows handling of the whole life-cycle of SAML-based federations and provides bindings for multiple languages.

Security Fix(es):

  • lasso: Type confusion in Entr'ouvert Lasso (CVE-2025-47151)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2412739 - CVE-2025-47151 lasso: Type confusion in Entr'ouvert Lasso

CVEs

  • CVE-2025-47151

References

  • https://access.redhat.com/security/updates/classification/#critical
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
lasso-2.5.1-8.el7_9.1.src.rpm SHA-256: 26ef40819f52ab1f6bb4f86a8b7fdad4384c8fe9f7fb17b0ac82dfc7fc75a50f
x86_64
lasso-2.5.1-8.el7_9.1.i686.rpm SHA-256: a5f99e658e99258b72e2e9a1bc7d887756e930eeac91b080f15ca238f5345bb0
lasso-2.5.1-8.el7_9.1.x86_64.rpm SHA-256: e163f3904526948057e46515211d4374c70f2d6e67d9e6ac93e5242840073ef6
lasso-debuginfo-2.5.1-8.el7_9.1.i686.rpm SHA-256: 5066118eee36711e7806baa08fcd56d7805802c06afd66b2b9bd85f3a729cecd
lasso-debuginfo-2.5.1-8.el7_9.1.i686.rpm SHA-256: 5066118eee36711e7806baa08fcd56d7805802c06afd66b2b9bd85f3a729cecd
lasso-debuginfo-2.5.1-8.el7_9.1.x86_64.rpm SHA-256: d7e4df32e70f84f2f4e3f71a22b7d54ec85a073f855b5b8891252003e1952ab1
lasso-debuginfo-2.5.1-8.el7_9.1.x86_64.rpm SHA-256: d7e4df32e70f84f2f4e3f71a22b7d54ec85a073f855b5b8891252003e1952ab1
lasso-devel-2.5.1-8.el7_9.1.i686.rpm SHA-256: 9b03d73512506607cb79ec9f082f82a99dae05fc7755a653484a80aec6c6d299
lasso-devel-2.5.1-8.el7_9.1.x86_64.rpm SHA-256: 9ec1ed709c31054e088779ca30331e0a479836848d371f03857c5390a0166a7d
lasso-python-2.5.1-8.el7_9.1.x86_64.rpm SHA-256: 70b34d54a4c195cad64a9d2c0cad695ee141f93bd40b0513575f422c0ba3f3d2

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
lasso-2.5.1-8.el7_9.1.src.rpm SHA-256: 26ef40819f52ab1f6bb4f86a8b7fdad4384c8fe9f7fb17b0ac82dfc7fc75a50f
s390x
lasso-2.5.1-8.el7_9.1.s390.rpm SHA-256: 63ed4e95acfd79e41c6e4261df0ceb64cc57d32ecfa4882cb6bcb47331b39587
lasso-2.5.1-8.el7_9.1.s390x.rpm SHA-256: 4b769eb99af143add15381c8157e2907a2ca1d270f36b0f56d9514e26cdae785
lasso-debuginfo-2.5.1-8.el7_9.1.s390.rpm SHA-256: eccca87f5b75bac2d720881c655a4a308128193f20321222d935a6b210ac17af
lasso-debuginfo-2.5.1-8.el7_9.1.s390.rpm SHA-256: eccca87f5b75bac2d720881c655a4a308128193f20321222d935a6b210ac17af
lasso-debuginfo-2.5.1-8.el7_9.1.s390x.rpm SHA-256: e2343341b64662d267a74aef3afefa0ee40640517add544e0563e8fb908f3555
lasso-debuginfo-2.5.1-8.el7_9.1.s390x.rpm SHA-256: e2343341b64662d267a74aef3afefa0ee40640517add544e0563e8fb908f3555
lasso-devel-2.5.1-8.el7_9.1.s390.rpm SHA-256: 359454d5ab36b530bda376a65f3a837ac34ce93431dea5ce6c3bc182917a35a4
lasso-devel-2.5.1-8.el7_9.1.s390x.rpm SHA-256: b08b649e6aac7371f17338ed893e6290fc57ee0a62898ba0d9d3105579280dfe
lasso-python-2.5.1-8.el7_9.1.s390x.rpm SHA-256: 28db46969c944186213eadc119b1c48ccd93854e92b99acec08d69bfc3e0e242

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
lasso-2.5.1-8.el7_9.1.src.rpm SHA-256: 26ef40819f52ab1f6bb4f86a8b7fdad4384c8fe9f7fb17b0ac82dfc7fc75a50f
ppc64
lasso-2.5.1-8.el7_9.1.ppc.rpm SHA-256: af2e61bcfe94f1b37a0db82727299a528e402be9eaa3b0827dc9fa2fc0b8d670
lasso-2.5.1-8.el7_9.1.ppc64.rpm SHA-256: 762e3e065485e447d41ecda33d073babe69bf2f2b807fe05e7918060ee67ebd8
lasso-debuginfo-2.5.1-8.el7_9.1.ppc.rpm SHA-256: 19522dca84800e2f975bb6be451f17b45d7c0b0c98d1cfa495652c2af128bef5
lasso-debuginfo-2.5.1-8.el7_9.1.ppc.rpm SHA-256: 19522dca84800e2f975bb6be451f17b45d7c0b0c98d1cfa495652c2af128bef5
lasso-debuginfo-2.5.1-8.el7_9.1.ppc64.rpm SHA-256: 950900f91ec4f06ee8e7c7ef2ebedaee234720dd30e4710b84f15333a70ee303
lasso-debuginfo-2.5.1-8.el7_9.1.ppc64.rpm SHA-256: 950900f91ec4f06ee8e7c7ef2ebedaee234720dd30e4710b84f15333a70ee303
lasso-devel-2.5.1-8.el7_9.1.ppc.rpm SHA-256: a97f03f898eaef0cc58d5be5d33688fa6d707ecf28e42cf55aab3e55b3ba9e64
lasso-devel-2.5.1-8.el7_9.1.ppc64.rpm SHA-256: bc3844d01a145149e10e95d975ae1cff13e9de1102b51f66849a896d226f6c0a
lasso-python-2.5.1-8.el7_9.1.ppc64.rpm SHA-256: 85036bda45e8aee18bc55e6eec20a88d63a5ca82490685f9ae5cdc6315c1ed4b

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
lasso-2.5.1-8.el7_9.1.src.rpm SHA-256: 26ef40819f52ab1f6bb4f86a8b7fdad4384c8fe9f7fb17b0ac82dfc7fc75a50f
ppc64le
lasso-2.5.1-8.el7_9.1.ppc64le.rpm SHA-256: fe704e9784bc5e9efdd4c1d34d5cdd96097ce39976ad0c04066392896d95b433
lasso-debuginfo-2.5.1-8.el7_9.1.ppc64le.rpm SHA-256: e7ad87ca9f350b90fe5c7bb280284d3f6b67dae32480e5701d5d80759d08b50a
lasso-debuginfo-2.5.1-8.el7_9.1.ppc64le.rpm SHA-256: e7ad87ca9f350b90fe5c7bb280284d3f6b67dae32480e5701d5d80759d08b50a
lasso-devel-2.5.1-8.el7_9.1.ppc64le.rpm SHA-256: 9ae56b79e5381e0a2a6365263ecdb0211695881501b2630967097cd4bf6b27aa
lasso-python-2.5.1-8.el7_9.1.ppc64le.rpm SHA-256: 4499b19c581738fdd5f598143134acab15f467649db90739c4de804ad8cf7a5a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility