Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8075 - Security Advisory
Issued:
2025-05-21
Updated:
2025-05-21

RHSA-2025:8075 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.8 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8 ppc64le
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2354195 - CVE-2025-30204 golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

CVEs

  • CVE-2025-30204

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8

SRPM
osbuild-composer-75-3.el8_8.src.rpm SHA-256: b24034d345a8f8e280834f6ff85dcecd488d06d6c8217a2e1df69944392e269e
x86_64
osbuild-composer-75-3.el8_8.x86_64.rpm SHA-256: b562653d24c1b5a7ac17724ff83b92b3ba6a5dcdaea9eccce2ed92bbd1885d98
osbuild-composer-core-75-3.el8_8.x86_64.rpm SHA-256: 18ce084945aba974a0fae223c07ec0fa7f1df8877a61eb50479737988321cdb4
osbuild-composer-core-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: ffa79ffdf3ebf0e1fa5ee538ff95aed7f3a13ae4b3bbccd8b198bea0b8188d7b
osbuild-composer-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: ef5d821d92c5c5dd49f32b75417d559673fbcabebc6dfc973298dbaa5e4e956b
osbuild-composer-debugsource-75-3.el8_8.x86_64.rpm SHA-256: 428253d2becfdaa9d04d6983aa2be450b1219f0ec7dd6a942b753fd652d12f08
osbuild-composer-dnf-json-75-3.el8_8.x86_64.rpm SHA-256: b9c696dbe3f69e73dcf4599edf6dd368a621a7fc2e4bb78e306f879025f576ae
osbuild-composer-tests-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: 719f80331688569ce2528aa966eaed917bba15e3786f478d5cf50c4187ece046
osbuild-composer-worker-75-3.el8_8.x86_64.rpm SHA-256: 129aa1f5c2e563fe11385244215f25be82742531c72932e8af9e897e349bb8c3
osbuild-composer-worker-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: f8d0bb323cc3458c1744dab9d90b4220e918fd2268017944ca2a3296497a8b16

Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8

SRPM
osbuild-composer-75-3.el8_8.src.rpm SHA-256: b24034d345a8f8e280834f6ff85dcecd488d06d6c8217a2e1df69944392e269e
x86_64
osbuild-composer-75-3.el8_8.x86_64.rpm SHA-256: b562653d24c1b5a7ac17724ff83b92b3ba6a5dcdaea9eccce2ed92bbd1885d98
osbuild-composer-core-75-3.el8_8.x86_64.rpm SHA-256: 18ce084945aba974a0fae223c07ec0fa7f1df8877a61eb50479737988321cdb4
osbuild-composer-core-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: ffa79ffdf3ebf0e1fa5ee538ff95aed7f3a13ae4b3bbccd8b198bea0b8188d7b
osbuild-composer-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: ef5d821d92c5c5dd49f32b75417d559673fbcabebc6dfc973298dbaa5e4e956b
osbuild-composer-debugsource-75-3.el8_8.x86_64.rpm SHA-256: 428253d2becfdaa9d04d6983aa2be450b1219f0ec7dd6a942b753fd652d12f08
osbuild-composer-dnf-json-75-3.el8_8.x86_64.rpm SHA-256: b9c696dbe3f69e73dcf4599edf6dd368a621a7fc2e4bb78e306f879025f576ae
osbuild-composer-tests-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: 719f80331688569ce2528aa966eaed917bba15e3786f478d5cf50c4187ece046
osbuild-composer-worker-75-3.el8_8.x86_64.rpm SHA-256: 129aa1f5c2e563fe11385244215f25be82742531c72932e8af9e897e349bb8c3
osbuild-composer-worker-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: f8d0bb323cc3458c1744dab9d90b4220e918fd2268017944ca2a3296497a8b16

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8

SRPM
osbuild-composer-75-3.el8_8.src.rpm SHA-256: b24034d345a8f8e280834f6ff85dcecd488d06d6c8217a2e1df69944392e269e
s390x
osbuild-composer-75-3.el8_8.s390x.rpm SHA-256: 7c23d9a5906f2aa5c8321e30156e5457637fd0550ef74a37881990c464d85a08
osbuild-composer-core-75-3.el8_8.s390x.rpm SHA-256: 0dcb50134df01b96cf5107a7376977fc0885e4489506fa0f5b433219372223f2
osbuild-composer-core-debuginfo-75-3.el8_8.s390x.rpm SHA-256: 35c9073d123de8add05c02e363f3eaa5756e80748ae476e390f8b401260bf399
osbuild-composer-debuginfo-75-3.el8_8.s390x.rpm SHA-256: 9d26eade496b9ca4509659c678b92f4e37dbb58a4d56a7c0f851f23bd0d26ce1
osbuild-composer-debugsource-75-3.el8_8.s390x.rpm SHA-256: ebb5de9c3c61be1183fdaa7729ca0e8edc3a382b34e7498d50ec4285804b8cb3
osbuild-composer-dnf-json-75-3.el8_8.s390x.rpm SHA-256: 6500e543fb411fb8eecd5b7c8d4c1c619c3ae08b5516e2dfa324e472624773a1
osbuild-composer-tests-debuginfo-75-3.el8_8.s390x.rpm SHA-256: c83dd7648c9e4aefcfbd0d20dcb43dd93b9be56490d949c5d500ed2afd286e66
osbuild-composer-worker-75-3.el8_8.s390x.rpm SHA-256: 23724db0ca0da41a64c0a92d3e8d326443f3be14661e71527f992e62ad75685c
osbuild-composer-worker-debuginfo-75-3.el8_8.s390x.rpm SHA-256: 97f1fac148f370dc6227e30274c645a72af4b16248eeade1d0125ddf82c62d90

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8

SRPM
osbuild-composer-75-3.el8_8.src.rpm SHA-256: b24034d345a8f8e280834f6ff85dcecd488d06d6c8217a2e1df69944392e269e
ppc64le
osbuild-composer-75-3.el8_8.ppc64le.rpm SHA-256: b544a69590e1d3405991cc59cba239d1b036c8c6f12094f471dd0b359508baad
osbuild-composer-core-75-3.el8_8.ppc64le.rpm SHA-256: 7dda62c213ce6da3dcb05d55e246c711dce39a28f8413ea0f85aa2af3b727894
osbuild-composer-core-debuginfo-75-3.el8_8.ppc64le.rpm SHA-256: dd7c5fc8f726b3dbf465950003191317c45aeae07506ef64591cc042082bd059
osbuild-composer-debuginfo-75-3.el8_8.ppc64le.rpm SHA-256: db2d67cf0817ae0e9987863adedc6e05ebf4227278b23974fb19974c43a6cf07
osbuild-composer-debugsource-75-3.el8_8.ppc64le.rpm SHA-256: 90f936160826af5733f9dc31e8e0f638138b1236d0275d2088804ca6ff93b007
osbuild-composer-dnf-json-75-3.el8_8.ppc64le.rpm SHA-256: 3b3b35fecb83d98a1a55885979887e467f0c93e6b0b0568423d690016cc61ed1
osbuild-composer-tests-debuginfo-75-3.el8_8.ppc64le.rpm SHA-256: 3d0db26f1afc0f67f59d48039d030a679f137e9212e1eeb0b922d387c395a5ff
osbuild-composer-worker-75-3.el8_8.ppc64le.rpm SHA-256: 56a6a477f2f692c9a4becc1a04fead2f5ea1800a33ed44735e5d9d7cd5546007
osbuild-composer-worker-debuginfo-75-3.el8_8.ppc64le.rpm SHA-256: 9674670e0872841478e01d521ff61d8d008af510de904b40e7191b9bf459c1ce

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
osbuild-composer-75-3.el8_8.src.rpm SHA-256: b24034d345a8f8e280834f6ff85dcecd488d06d6c8217a2e1df69944392e269e
x86_64
osbuild-composer-75-3.el8_8.x86_64.rpm SHA-256: b562653d24c1b5a7ac17724ff83b92b3ba6a5dcdaea9eccce2ed92bbd1885d98
osbuild-composer-core-75-3.el8_8.x86_64.rpm SHA-256: 18ce084945aba974a0fae223c07ec0fa7f1df8877a61eb50479737988321cdb4
osbuild-composer-core-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: ffa79ffdf3ebf0e1fa5ee538ff95aed7f3a13ae4b3bbccd8b198bea0b8188d7b
osbuild-composer-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: ef5d821d92c5c5dd49f32b75417d559673fbcabebc6dfc973298dbaa5e4e956b
osbuild-composer-debugsource-75-3.el8_8.x86_64.rpm SHA-256: 428253d2becfdaa9d04d6983aa2be450b1219f0ec7dd6a942b753fd652d12f08
osbuild-composer-dnf-json-75-3.el8_8.x86_64.rpm SHA-256: b9c696dbe3f69e73dcf4599edf6dd368a621a7fc2e4bb78e306f879025f576ae
osbuild-composer-tests-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: 719f80331688569ce2528aa966eaed917bba15e3786f478d5cf50c4187ece046
osbuild-composer-worker-75-3.el8_8.x86_64.rpm SHA-256: 129aa1f5c2e563fe11385244215f25be82742531c72932e8af9e897e349bb8c3
osbuild-composer-worker-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: f8d0bb323cc3458c1744dab9d90b4220e918fd2268017944ca2a3296497a8b16

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8

SRPM
osbuild-composer-75-3.el8_8.src.rpm SHA-256: b24034d345a8f8e280834f6ff85dcecd488d06d6c8217a2e1df69944392e269e
aarch64
osbuild-composer-75-3.el8_8.aarch64.rpm SHA-256: dc5c59d347a8ea2e00fc343831950bcae512bb53284a13a68059be71c6b0d3d6
osbuild-composer-core-75-3.el8_8.aarch64.rpm SHA-256: bf1ab0bdc5b8d8b7e60ef0c7b6fa617a26d355159f6f825286167c1f07d1d620
osbuild-composer-core-debuginfo-75-3.el8_8.aarch64.rpm SHA-256: 7306feae1df59820b4cb19b71b66f1bd53f61442963d42897c53cd7ad69a3e43
osbuild-composer-debuginfo-75-3.el8_8.aarch64.rpm SHA-256: 8e6368be840d255c600bc9798f357636ba34a1fc8dbf6ba23688f252c417daa8
osbuild-composer-debugsource-75-3.el8_8.aarch64.rpm SHA-256: 29231f717118fb6bd8b1db7bfdd93858001f3246ddbb430910fe69ae47a14679
osbuild-composer-dnf-json-75-3.el8_8.aarch64.rpm SHA-256: 4cbfbb944867ac106f3088c2034d1a091813ae259ac4230d660bb10c1ae5f145
osbuild-composer-tests-debuginfo-75-3.el8_8.aarch64.rpm SHA-256: 744bc4b8a57b2c76ca1e79b584a3d4297c76f51dd6cb7ee115955f87f372feac
osbuild-composer-worker-75-3.el8_8.aarch64.rpm SHA-256: 4b6a9ace6d282dd406260d6dff2a3363eb9d30753faf080518e5109c683e8e1b
osbuild-composer-worker-debuginfo-75-3.el8_8.aarch64.rpm SHA-256: 7ec9aa2495a502597bcc956065ebfb78c99156f4fe4155e16e3499f874c2156d

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
osbuild-composer-75-3.el8_8.src.rpm SHA-256: b24034d345a8f8e280834f6ff85dcecd488d06d6c8217a2e1df69944392e269e
ppc64le
osbuild-composer-75-3.el8_8.ppc64le.rpm SHA-256: b544a69590e1d3405991cc59cba239d1b036c8c6f12094f471dd0b359508baad
osbuild-composer-core-75-3.el8_8.ppc64le.rpm SHA-256: 7dda62c213ce6da3dcb05d55e246c711dce39a28f8413ea0f85aa2af3b727894
osbuild-composer-core-debuginfo-75-3.el8_8.ppc64le.rpm SHA-256: dd7c5fc8f726b3dbf465950003191317c45aeae07506ef64591cc042082bd059
osbuild-composer-debuginfo-75-3.el8_8.ppc64le.rpm SHA-256: db2d67cf0817ae0e9987863adedc6e05ebf4227278b23974fb19974c43a6cf07
osbuild-composer-debugsource-75-3.el8_8.ppc64le.rpm SHA-256: 90f936160826af5733f9dc31e8e0f638138b1236d0275d2088804ca6ff93b007
osbuild-composer-dnf-json-75-3.el8_8.ppc64le.rpm SHA-256: 3b3b35fecb83d98a1a55885979887e467f0c93e6b0b0568423d690016cc61ed1
osbuild-composer-tests-debuginfo-75-3.el8_8.ppc64le.rpm SHA-256: 3d0db26f1afc0f67f59d48039d030a679f137e9212e1eeb0b922d387c395a5ff
osbuild-composer-worker-75-3.el8_8.ppc64le.rpm SHA-256: 56a6a477f2f692c9a4becc1a04fead2f5ea1800a33ed44735e5d9d7cd5546007
osbuild-composer-worker-debuginfo-75-3.el8_8.ppc64le.rpm SHA-256: 9674670e0872841478e01d521ff61d8d008af510de904b40e7191b9bf459c1ce

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
osbuild-composer-75-3.el8_8.src.rpm SHA-256: b24034d345a8f8e280834f6ff85dcecd488d06d6c8217a2e1df69944392e269e
x86_64
osbuild-composer-75-3.el8_8.x86_64.rpm SHA-256: b562653d24c1b5a7ac17724ff83b92b3ba6a5dcdaea9eccce2ed92bbd1885d98
osbuild-composer-core-75-3.el8_8.x86_64.rpm SHA-256: 18ce084945aba974a0fae223c07ec0fa7f1df8877a61eb50479737988321cdb4
osbuild-composer-core-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: ffa79ffdf3ebf0e1fa5ee538ff95aed7f3a13ae4b3bbccd8b198bea0b8188d7b
osbuild-composer-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: ef5d821d92c5c5dd49f32b75417d559673fbcabebc6dfc973298dbaa5e4e956b
osbuild-composer-debugsource-75-3.el8_8.x86_64.rpm SHA-256: 428253d2becfdaa9d04d6983aa2be450b1219f0ec7dd6a942b753fd652d12f08
osbuild-composer-dnf-json-75-3.el8_8.x86_64.rpm SHA-256: b9c696dbe3f69e73dcf4599edf6dd368a621a7fc2e4bb78e306f879025f576ae
osbuild-composer-tests-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: 719f80331688569ce2528aa966eaed917bba15e3786f478d5cf50c4187ece046
osbuild-composer-worker-75-3.el8_8.x86_64.rpm SHA-256: 129aa1f5c2e563fe11385244215f25be82742531c72932e8af9e897e349bb8c3
osbuild-composer-worker-debuginfo-75-3.el8_8.x86_64.rpm SHA-256: f8d0bb323cc3458c1744dab9d90b4220e918fd2268017944ca2a3296497a8b16

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility