Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:0314 - Security Advisory
发布:
2026-01-08
已更新:
2026-01-08

RHSA-2026:0314 - Security Advisory

  • 概述
  • 更新的软件包

概述

Moderate: osbuild-composer security update

类型/严重性

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for osbuild-composer is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

修复

  • BZ - 2407258 - CVE-2025-58183 golang: archive/tar: Unbounded allocation when parsing GNU sparse map

CVE

  • CVE-2025-58183

参考

  • https://access.redhat.com/security/updates/classification/#moderate
注:: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
osbuild-composer-76.1-3.el9_2.src.rpm SHA-256: 6a821ce52437154905f31a318ee46878b46c9d3047958f2eeac803df9ae533b6
x86_64
osbuild-composer-76.1-3.el9_2.x86_64.rpm SHA-256: 24a7fb611ef814f5b3ea06e5de246aada1eb8c757ec4eef6641342ae653bd8a4
osbuild-composer-core-76.1-3.el9_2.x86_64.rpm SHA-256: 88dd8b8989428f97693ff76d4668ccc56f1a00b7c7804e590b65205a7616845f
osbuild-composer-core-debuginfo-76.1-3.el9_2.x86_64.rpm SHA-256: dee1f1c6b0f634518409f594526131bc289547a6f479b6038a77ac429b9e04e6
osbuild-composer-debuginfo-76.1-3.el9_2.x86_64.rpm SHA-256: 9e3719cf9fa867a1e043877883cb9503316d4f302dd7462d3c83f7304918cdbb
osbuild-composer-debugsource-76.1-3.el9_2.x86_64.rpm SHA-256: acddadd2ccc8e4545b525f446b5810f91740e418cef162acf9edd0bf0375a94f
osbuild-composer-dnf-json-76.1-3.el9_2.x86_64.rpm SHA-256: 89149d309f1b3c92f5bb6906b2d62a0eeec6912e644e34e16cb19093a917ec45
osbuild-composer-tests-debuginfo-76.1-3.el9_2.x86_64.rpm SHA-256: cd73099cffeaa8ea35bf0a68807c21109f0fc74f3eacb62ed44b26b962daf101
osbuild-composer-worker-76.1-3.el9_2.x86_64.rpm SHA-256: b235c1de0911e01ebc31d948e0092eceb39ed328c6d9b948da37c1df2efd2075
osbuild-composer-worker-debuginfo-76.1-3.el9_2.x86_64.rpm SHA-256: 5d63d47ede73302a6d3da769df1329315822057a2e90901be47f92de4c6e29fb

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
osbuild-composer-76.1-3.el9_2.src.rpm SHA-256: 6a821ce52437154905f31a318ee46878b46c9d3047958f2eeac803df9ae533b6
ppc64le
osbuild-composer-76.1-3.el9_2.ppc64le.rpm SHA-256: e4f302355a66c3b110dde08b90b1b5fc2bbf564b431f7341c6bcfd5025dd537f
osbuild-composer-core-76.1-3.el9_2.ppc64le.rpm SHA-256: 93d7eb3ca7073d8815db7aa8e666a106f61e9a5e307cb399a936d7872e93384d
osbuild-composer-core-debuginfo-76.1-3.el9_2.ppc64le.rpm SHA-256: 0d83e3217d9bae9cf99dd026a9ae81a86f709c90e9d7a48a2b86f81ab614aa5d
osbuild-composer-debuginfo-76.1-3.el9_2.ppc64le.rpm SHA-256: 67d86ea55c6ff7c2392ad5e3cf6f1172f6c2de7ab06c43755e5434d9d85d2359
osbuild-composer-debugsource-76.1-3.el9_2.ppc64le.rpm SHA-256: 56e87ec7632cd3773efa9ba43c37502031437c3b56ff35d92d5e0643ea566951
osbuild-composer-dnf-json-76.1-3.el9_2.ppc64le.rpm SHA-256: 7c5f3b7a98c94a400e3229c3fc9a18f7ed367c170be39d3439695ed063c85e74
osbuild-composer-tests-debuginfo-76.1-3.el9_2.ppc64le.rpm SHA-256: 36f6beecc579fd7cf599c0ce5e0f5a562efe515908779d9f06f19495ff190f3f
osbuild-composer-worker-76.1-3.el9_2.ppc64le.rpm SHA-256: 34eea4d86a640aeb069cd6fe10959f94a29e2bca13edeced25d547e225984812
osbuild-composer-worker-debuginfo-76.1-3.el9_2.ppc64le.rpm SHA-256: ab1e8093f2c1764b68d70df3ed443fafc1409414bc6c13e407e43099ef2e8d1e

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
osbuild-composer-76.1-3.el9_2.src.rpm SHA-256: 6a821ce52437154905f31a318ee46878b46c9d3047958f2eeac803df9ae533b6
x86_64
osbuild-composer-76.1-3.el9_2.x86_64.rpm SHA-256: 24a7fb611ef814f5b3ea06e5de246aada1eb8c757ec4eef6641342ae653bd8a4
osbuild-composer-core-76.1-3.el9_2.x86_64.rpm SHA-256: 88dd8b8989428f97693ff76d4668ccc56f1a00b7c7804e590b65205a7616845f
osbuild-composer-core-debuginfo-76.1-3.el9_2.x86_64.rpm SHA-256: dee1f1c6b0f634518409f594526131bc289547a6f479b6038a77ac429b9e04e6
osbuild-composer-debuginfo-76.1-3.el9_2.x86_64.rpm SHA-256: 9e3719cf9fa867a1e043877883cb9503316d4f302dd7462d3c83f7304918cdbb
osbuild-composer-debugsource-76.1-3.el9_2.x86_64.rpm SHA-256: acddadd2ccc8e4545b525f446b5810f91740e418cef162acf9edd0bf0375a94f
osbuild-composer-dnf-json-76.1-3.el9_2.x86_64.rpm SHA-256: 89149d309f1b3c92f5bb6906b2d62a0eeec6912e644e34e16cb19093a917ec45
osbuild-composer-tests-debuginfo-76.1-3.el9_2.x86_64.rpm SHA-256: cd73099cffeaa8ea35bf0a68807c21109f0fc74f3eacb62ed44b26b962daf101
osbuild-composer-worker-76.1-3.el9_2.x86_64.rpm SHA-256: b235c1de0911e01ebc31d948e0092eceb39ed328c6d9b948da37c1df2efd2075
osbuild-composer-worker-debuginfo-76.1-3.el9_2.x86_64.rpm SHA-256: 5d63d47ede73302a6d3da769df1329315822057a2e90901be47f92de4c6e29fb

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
osbuild-composer-76.1-3.el9_2.src.rpm SHA-256: 6a821ce52437154905f31a318ee46878b46c9d3047958f2eeac803df9ae533b6
aarch64
osbuild-composer-76.1-3.el9_2.aarch64.rpm SHA-256: 84caccba56bd4ca550e3e5a07028c96880803bb9af61c5d638d2562c7e048dbb
osbuild-composer-core-76.1-3.el9_2.aarch64.rpm SHA-256: 35fef00264403e7e277c0fca21fe0b246d0d4068f73329f34f6597371c905fc1
osbuild-composer-core-debuginfo-76.1-3.el9_2.aarch64.rpm SHA-256: 89cfe5f25a09c8579f102bc56bdfeaaaf8a048a927c680e314e168f214d9530f
osbuild-composer-debuginfo-76.1-3.el9_2.aarch64.rpm SHA-256: 22f5a0efe8a84e58f8398a5acd1be9af99527b96ec5887c25069cba7605268ee
osbuild-composer-debugsource-76.1-3.el9_2.aarch64.rpm SHA-256: 9425fb1cfa5f5da69910f6e9bb7d65967ca6585fd8bad9884672c675923443ef
osbuild-composer-dnf-json-76.1-3.el9_2.aarch64.rpm SHA-256: 61cada2bef239fec4710a48bcbcb9b171773e15b49b6342a69df99cd5847e3cd
osbuild-composer-tests-debuginfo-76.1-3.el9_2.aarch64.rpm SHA-256: 2ab659b6d8d65689f2cb8124f5ce9bbd0634acd246c79e1815136402ed5499d9
osbuild-composer-worker-76.1-3.el9_2.aarch64.rpm SHA-256: 5ab418cbfb695d5f9239921a8b4a1527976d62e77aa6f3a29c9ea69bd17ba284
osbuild-composer-worker-debuginfo-76.1-3.el9_2.aarch64.rpm SHA-256: 5db3b08606d4a6dba459e5a69813d1513a8a6bb1737571cb73dac94a4de16eee

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
osbuild-composer-76.1-3.el9_2.src.rpm SHA-256: 6a821ce52437154905f31a318ee46878b46c9d3047958f2eeac803df9ae533b6
s390x
osbuild-composer-76.1-3.el9_2.s390x.rpm SHA-256: 41d02c08b6b69ea9c889b2acb95f34ba0ee149b059ffdd21c6bdf511c7dab2cc
osbuild-composer-core-76.1-3.el9_2.s390x.rpm SHA-256: 3b91ea563b88bf85aeb90075218f5ea2e345a49df93dbcaa9b3a8835b8ba17ff
osbuild-composer-core-debuginfo-76.1-3.el9_2.s390x.rpm SHA-256: 726f186e914d43b52f4171eb2e8e99f41b62dc3a035a0d459852b2a00af85a67
osbuild-composer-debuginfo-76.1-3.el9_2.s390x.rpm SHA-256: bb188a4229bc8dad0413778e10fa532f42a453b118a1365282949136b4f65aa0
osbuild-composer-debugsource-76.1-3.el9_2.s390x.rpm SHA-256: 5deb2056a651be10b904022cb3844103896e9192771a0dc42ff6a45cc80d87df
osbuild-composer-dnf-json-76.1-3.el9_2.s390x.rpm SHA-256: 5dd6a1b080b9a6dbdf9fc0529ebe693d94de8fe8f49c38aaa4621f70e4c48e9b
osbuild-composer-tests-debuginfo-76.1-3.el9_2.s390x.rpm SHA-256: 67aeef79bdf57a5c25d60210da0dc1e85439bb1cf6d4532f3f6b3fd9ab0f86e3
osbuild-composer-worker-76.1-3.el9_2.s390x.rpm SHA-256: fadb2615ca5289981dea45cc337c1264c1d5918aa7efaef3aff96dc9568483cb
osbuild-composer-worker-debuginfo-76.1-3.el9_2.s390x.rpm SHA-256: b485e71cc56724500c7d28a985b80a9fdf61b885d220d619b3c787ee6f1c74eb

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility