Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0227 - Security Advisory
Issued:
2026-01-07
Updated:
2026-01-07

RHSA-2026:0227 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: osbuild-composer security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2407258 - CVE-2025-58183 golang: archive/tar: Unbounded allocation when parsing GNU sparse map

CVEs

  • CVE-2025-58183

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
osbuild-composer-46.3-5.el9_0.src.rpm SHA-256: 1f9a61714a5adc92d53d004e1a186e6c569de410f36afed027709c09d79bef94
ppc64le
osbuild-composer-46.3-5.el9_0.ppc64le.rpm SHA-256: 4446e112c349826acd94edbd0213821522fa6d7aa42fad3f1a30967cd81d5e29
osbuild-composer-core-46.3-5.el9_0.ppc64le.rpm SHA-256: a70d96e0ad99f49b7e800f8666199dae692986e6a069ca336513b6aeaf673d2f
osbuild-composer-core-debuginfo-46.3-5.el9_0.ppc64le.rpm SHA-256: c9a49dd97a1b7bf645e1b2af3a2f72d63f118d24008af166f12e1d83e83bee82
osbuild-composer-debugsource-46.3-5.el9_0.ppc64le.rpm SHA-256: 57c0772fbeb1d30397b8f03bf9a4437045228460d0c5b2cd5f8f0b9d8b992ac3
osbuild-composer-dnf-json-46.3-5.el9_0.ppc64le.rpm SHA-256: 6650a3d684520b918ddde5d90d8fd0d6bac254264e36d3895460b4291693daf8
osbuild-composer-tests-debuginfo-46.3-5.el9_0.ppc64le.rpm SHA-256: fab505c397665307b250dfe805c6827b013b8ff45815fbfb66cd728bf754d91a
osbuild-composer-worker-46.3-5.el9_0.ppc64le.rpm SHA-256: fa0f1da2d91e8d3541d4f0c04d77c34b7406cb58f57ea7b02a6a0ffe70298830
osbuild-composer-worker-debuginfo-46.3-5.el9_0.ppc64le.rpm SHA-256: 915ce1cf4f11b7d24b7423792ebf046d47698898df7d1422ea6074ac294b3ed5

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
osbuild-composer-46.3-5.el9_0.src.rpm SHA-256: 1f9a61714a5adc92d53d004e1a186e6c569de410f36afed027709c09d79bef94
x86_64
osbuild-composer-46.3-5.el9_0.x86_64.rpm SHA-256: d21ae12dc4cf62f75fe3ae5f26d3fcd66a4d28701e37babda8fa40bba84cf792
osbuild-composer-core-46.3-5.el9_0.x86_64.rpm SHA-256: f741f456eee49b861f6ae0da249b42b9f0aada53c2ae6863ff072ae61bc4966a
osbuild-composer-core-debuginfo-46.3-5.el9_0.x86_64.rpm SHA-256: 3dab6dcf2ae5017fb22f8287aea28cd1fb59fda99ac149bc111e9575ce6643ba
osbuild-composer-debugsource-46.3-5.el9_0.x86_64.rpm SHA-256: 0f7623f91f4cdad26fd0608cdb0876ba3608da6b3f631bd46d67b9a135105d74
osbuild-composer-dnf-json-46.3-5.el9_0.x86_64.rpm SHA-256: 83334c84bcf07635676f57dd150e0e6a6db3b16f406557aff8ab2caa22f51a47
osbuild-composer-tests-debuginfo-46.3-5.el9_0.x86_64.rpm SHA-256: 46c7b1023659fd180c8267614c76a055d2fbdcbd6a9424c9e9eb634b119c1371
osbuild-composer-worker-46.3-5.el9_0.x86_64.rpm SHA-256: 203cf9452ce138a32ee47a2f415808caf9bf6057b6850adb48f8dada7862030a
osbuild-composer-worker-debuginfo-46.3-5.el9_0.x86_64.rpm SHA-256: ecabf02444fa160fafbfd37000a3dbcb8b2b5891245917b6ead939ec7e8b5805

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
osbuild-composer-46.3-5.el9_0.src.rpm SHA-256: 1f9a61714a5adc92d53d004e1a186e6c569de410f36afed027709c09d79bef94
aarch64
osbuild-composer-46.3-5.el9_0.aarch64.rpm SHA-256: 524f04c3c7e63ef53a4ae7204f68208ff544a5321d40814103e0a1b1530481c3
osbuild-composer-core-46.3-5.el9_0.aarch64.rpm SHA-256: ce1a95da27bd2e29b64ffa4281beb4992c5e339f4847e2abad8863819a36c3fd
osbuild-composer-core-debuginfo-46.3-5.el9_0.aarch64.rpm SHA-256: 2b4c566e1c6293e8f139a28bee746c643464d635c669436c4ceed0e40df72fe9
osbuild-composer-debugsource-46.3-5.el9_0.aarch64.rpm SHA-256: 4e9a95e99a14c65a249b4544b75edd16edb75c81d8049f714545389ed52c6b08
osbuild-composer-dnf-json-46.3-5.el9_0.aarch64.rpm SHA-256: 62f30b54a27aff9014b167bf5a6f28ac926c8c4d4c3701fc6fcee61138275cb5
osbuild-composer-tests-debuginfo-46.3-5.el9_0.aarch64.rpm SHA-256: f1feb8187a6e8994081278855e7b251a5cfef409741d570ae141fc9fbf5a1162
osbuild-composer-worker-46.3-5.el9_0.aarch64.rpm SHA-256: 56677cc457fcbf685473dff8e52e35ab58ff0aaebc7b2939c4669d2a12bfebf4
osbuild-composer-worker-debuginfo-46.3-5.el9_0.aarch64.rpm SHA-256: f8fbc69cda88b03811ee4157765d3cc7d8f7c56c555b412a3c4aeaa712238f9d

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
osbuild-composer-46.3-5.el9_0.src.rpm SHA-256: 1f9a61714a5adc92d53d004e1a186e6c569de410f36afed027709c09d79bef94
s390x
osbuild-composer-46.3-5.el9_0.s390x.rpm SHA-256: 7d1f3e8ee6fa7ca6a7db1f9b2d4fa335e505a939eee4f555ac527ef968aacdab
osbuild-composer-core-46.3-5.el9_0.s390x.rpm SHA-256: 7f094106fc8f96352af11ccdac1f545e4a7f9fa62061b6993fc5de5c7460b164
osbuild-composer-core-debuginfo-46.3-5.el9_0.s390x.rpm SHA-256: 51bf2ea5f7fe065a5ec10f7a213db57226332cb73a13a5000fa8566e93d3028d
osbuild-composer-debugsource-46.3-5.el9_0.s390x.rpm SHA-256: ec70dda1184c05629410c6d8a2f7fe57354eab2c24cbbcd4270f804a490c13d9
osbuild-composer-dnf-json-46.3-5.el9_0.s390x.rpm SHA-256: ce8fe40997ad6c94fc2a9f283734eb6eec2e163a82e3b3ce86d08d738205dc8d
osbuild-composer-tests-debuginfo-46.3-5.el9_0.s390x.rpm SHA-256: b27043edc5ff61dc1248e68b73cc255e6494aad7adeb7f468cc837e001847a7b
osbuild-composer-worker-46.3-5.el9_0.s390x.rpm SHA-256: 5c0cc836e3023518f80fdc691c74d1b4162abd464dafae7262d470fd0cae026e
osbuild-composer-worker-debuginfo-46.3-5.el9_0.s390x.rpm SHA-256: 78694e9249306858a7682f269bceddbddd8f0c59eb8ee2448ae508d45a9de8b5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility