Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:21634 - Security Advisory
Issued:
2025-11-18
Updated:
2025-11-18

RHSA-2025:21634 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: buildah security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for buildah is now available for Red Hat Enterprise Linux 9.6 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x

Fixes

  • BZ - 2404715 - CVE-2025-52881 runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects

CVEs

  • CVE-2025-52881

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
x86_64
buildah-1.39.5-1.el9_6.x86_64.rpm SHA-256: aae43426239c53f32f6b7e06034f965f8c9934f7bf6871096b9cdc025d66a5c3
buildah-debuginfo-1.39.5-1.el9_6.x86_64.rpm SHA-256: 0b462fe8ed33549866d4aea7c5bceba11e8bd936f7ab4a3868f00152b819753b
buildah-debugsource-1.39.5-1.el9_6.x86_64.rpm SHA-256: 377858ab829eee3cec0aa35d1ddf2efeebb967628cc428e26aa693ea4cad605b
buildah-tests-1.39.5-1.el9_6.x86_64.rpm SHA-256: a22dfd88542daa968de2cc86bcfa7c8e7b3b93fb90a38f34defb7151c2967be3
buildah-tests-debuginfo-1.39.5-1.el9_6.x86_64.rpm SHA-256: 619e657b8864f96a7682874f8ce4d7318b7805ab70108a7c89b0849fb59f56c9

Red Hat Enterprise Linux Server - AUS 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
x86_64
buildah-1.39.5-1.el9_6.x86_64.rpm SHA-256: aae43426239c53f32f6b7e06034f965f8c9934f7bf6871096b9cdc025d66a5c3
buildah-debuginfo-1.39.5-1.el9_6.x86_64.rpm SHA-256: 0b462fe8ed33549866d4aea7c5bceba11e8bd936f7ab4a3868f00152b819753b
buildah-debugsource-1.39.5-1.el9_6.x86_64.rpm SHA-256: 377858ab829eee3cec0aa35d1ddf2efeebb967628cc428e26aa693ea4cad605b
buildah-tests-1.39.5-1.el9_6.x86_64.rpm SHA-256: a22dfd88542daa968de2cc86bcfa7c8e7b3b93fb90a38f34defb7151c2967be3
buildah-tests-debuginfo-1.39.5-1.el9_6.x86_64.rpm SHA-256: 619e657b8864f96a7682874f8ce4d7318b7805ab70108a7c89b0849fb59f56c9

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
s390x
buildah-1.39.5-1.el9_6.s390x.rpm SHA-256: 979043ea2d63aa5858dfaff075382b4db7f82163dfb907d18e537ff92e1bc5fb
buildah-debuginfo-1.39.5-1.el9_6.s390x.rpm SHA-256: 6ded77d41e9d75aad291bda0aa5e4a1c428694d9dad96012a6625db2f2b5f4d0
buildah-debugsource-1.39.5-1.el9_6.s390x.rpm SHA-256: b4d69b387b24e5439fb2835b5142451dcd022196282735ab98679aa001e7b76f
buildah-tests-1.39.5-1.el9_6.s390x.rpm SHA-256: c1fafef4b1bb1708c9c4357f5bc76b859d29bbf8ce072a3980ed890bda036029
buildah-tests-debuginfo-1.39.5-1.el9_6.s390x.rpm SHA-256: 52d0f79fe53340e6451272d3dc6c57551a96384d5739604478ebccd6857c9ee7

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
ppc64le
buildah-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 1198f62a59f54c1ddd9575cd38ee78cde0101f05cdead6b0f95b0c7794eaa663
buildah-debuginfo-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 2f0af68dc8d7f7f3a5ea1ff64a8cfe8708322fd1c9e373c593b9369f13bac277
buildah-debugsource-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 430d240a8ce9675416c8714949a7a9b3d3c02571a9d0cfac030f1e4806a671e4
buildah-tests-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 65c3206186f33feb50ff0d494cddf7039184ad50f3e6b2f78b85dfe13f5ff41a
buildah-tests-debuginfo-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 4cf0a54296df658356108b7f23af7e8578816727a63eef352408d98d87e95518

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
aarch64
buildah-1.39.5-1.el9_6.aarch64.rpm SHA-256: 0f46b3e3cd9e93bebc2726510c19ed84fc7315151512295c1b0aeacda8727386
buildah-debuginfo-1.39.5-1.el9_6.aarch64.rpm SHA-256: 48b3773a3f27e3f1e5f02e027c3db4f33c5c3e4d9a6b7a8f498975776cd97df1
buildah-debugsource-1.39.5-1.el9_6.aarch64.rpm SHA-256: cf2d5e112753d110f1400d4d6328813eb058878d31dd3a47a5f1f1ac6612e698
buildah-tests-1.39.5-1.el9_6.aarch64.rpm SHA-256: f7195fa05e4327de91470ffb1c8af18b9a8a444664f803e1b85c163faeeb1493
buildah-tests-debuginfo-1.39.5-1.el9_6.aarch64.rpm SHA-256: 074f56d3cc5a4ed8b4fc00d4a09043e2ff7b537d061bf8f9b9c0b0586cfb806a

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
ppc64le
buildah-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 1198f62a59f54c1ddd9575cd38ee78cde0101f05cdead6b0f95b0c7794eaa663
buildah-debuginfo-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 2f0af68dc8d7f7f3a5ea1ff64a8cfe8708322fd1c9e373c593b9369f13bac277
buildah-debugsource-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 430d240a8ce9675416c8714949a7a9b3d3c02571a9d0cfac030f1e4806a671e4
buildah-tests-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 65c3206186f33feb50ff0d494cddf7039184ad50f3e6b2f78b85dfe13f5ff41a
buildah-tests-debuginfo-1.39.5-1.el9_6.ppc64le.rpm SHA-256: 4cf0a54296df658356108b7f23af7e8578816727a63eef352408d98d87e95518

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
x86_64
buildah-1.39.5-1.el9_6.x86_64.rpm SHA-256: aae43426239c53f32f6b7e06034f965f8c9934f7bf6871096b9cdc025d66a5c3
buildah-debuginfo-1.39.5-1.el9_6.x86_64.rpm SHA-256: 0b462fe8ed33549866d4aea7c5bceba11e8bd936f7ab4a3868f00152b819753b
buildah-debugsource-1.39.5-1.el9_6.x86_64.rpm SHA-256: 377858ab829eee3cec0aa35d1ddf2efeebb967628cc428e26aa693ea4cad605b
buildah-tests-1.39.5-1.el9_6.x86_64.rpm SHA-256: a22dfd88542daa968de2cc86bcfa7c8e7b3b93fb90a38f34defb7151c2967be3
buildah-tests-debuginfo-1.39.5-1.el9_6.x86_64.rpm SHA-256: 619e657b8864f96a7682874f8ce4d7318b7805ab70108a7c89b0849fb59f56c9

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
aarch64
buildah-1.39.5-1.el9_6.aarch64.rpm SHA-256: 0f46b3e3cd9e93bebc2726510c19ed84fc7315151512295c1b0aeacda8727386
buildah-debuginfo-1.39.5-1.el9_6.aarch64.rpm SHA-256: 48b3773a3f27e3f1e5f02e027c3db4f33c5c3e4d9a6b7a8f498975776cd97df1
buildah-debugsource-1.39.5-1.el9_6.aarch64.rpm SHA-256: cf2d5e112753d110f1400d4d6328813eb058878d31dd3a47a5f1f1ac6612e698
buildah-tests-1.39.5-1.el9_6.aarch64.rpm SHA-256: f7195fa05e4327de91470ffb1c8af18b9a8a444664f803e1b85c163faeeb1493
buildah-tests-debuginfo-1.39.5-1.el9_6.aarch64.rpm SHA-256: 074f56d3cc5a4ed8b4fc00d4a09043e2ff7b537d061bf8f9b9c0b0586cfb806a

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6

SRPM
buildah-1.39.5-1.el9_6.src.rpm SHA-256: 5160881f6d67c9c0f24a4ab98b4071eee04849b0fc2ff397f8466f9dc30d5f82
s390x
buildah-1.39.5-1.el9_6.s390x.rpm SHA-256: 979043ea2d63aa5858dfaff075382b4db7f82163dfb907d18e537ff92e1bc5fb
buildah-debuginfo-1.39.5-1.el9_6.s390x.rpm SHA-256: 6ded77d41e9d75aad291bda0aa5e4a1c428694d9dad96012a6625db2f2b5f4d0
buildah-debugsource-1.39.5-1.el9_6.s390x.rpm SHA-256: b4d69b387b24e5439fb2835b5142451dcd022196282735ab98679aa001e7b76f
buildah-tests-1.39.5-1.el9_6.s390x.rpm SHA-256: c1fafef4b1bb1708c9c4357f5bc76b859d29bbf8ce072a3980ed890bda036029
buildah-tests-debuginfo-1.39.5-1.el9_6.s390x.rpm SHA-256: 52d0f79fe53340e6451272d3dc6c57551a96384d5739604478ebccd6857c9ee7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility