Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0436 - Security Advisory
Issued:
2026-01-12
Updated:
2026-01-12

RHSA-2026:0436 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: buildah security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for buildah is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2414943 - CVE-2025-47913 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS

CVEs

  • CVE-2025-47913

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
buildah-1.41.8-1.el10_1.src.rpm SHA-256: cde36d0478749903ccc62630a2b49bc09f43840eb3134b2df733a1cd5978256c
x86_64
buildah-1.41.8-1.el10_1.x86_64.rpm SHA-256: fc78bc2b1a1e39c081b7d3d34405fc6b2db4c531cc929648a5bf1242ad5f0083
buildah-debuginfo-1.41.8-1.el10_1.x86_64.rpm SHA-256: acebebd1fda0b37a4ee786ecb91e7b3af7a2bdc44b6e7f2b8b8fd8c4dbd986b7
buildah-debugsource-1.41.8-1.el10_1.x86_64.rpm SHA-256: e954b8852bfa1314c62c0aaa7a154adbbd876f42b1ba7c047c480f70f2377dcd
buildah-tests-1.41.8-1.el10_1.x86_64.rpm SHA-256: 56339d2da2963ae407299cce4f214baf6bb4b4fed45d8c2f50b2dc237bd7e4e6
buildah-tests-debuginfo-1.41.8-1.el10_1.x86_64.rpm SHA-256: c5cb3e38e5f13e1301a099f4e70fe48b68a0bf5b0597951e82926a0e287c92ea

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
buildah-1.41.8-1.el10_1.src.rpm SHA-256: cde36d0478749903ccc62630a2b49bc09f43840eb3134b2df733a1cd5978256c
s390x
buildah-1.41.8-1.el10_1.s390x.rpm SHA-256: e9ea9e1b40eaac39e63ff80ffe2cf9157fe7d91afcce69f0d4f75cb7e178ab17
buildah-debuginfo-1.41.8-1.el10_1.s390x.rpm SHA-256: e0e86ecb450b7cf56cfc17be0fa5d05096af38194289fde8c5ac83176a3403f0
buildah-debugsource-1.41.8-1.el10_1.s390x.rpm SHA-256: 7cbf078c82174e1147cb2d61c889d47e103ba15ef65264e8410982341fb36c9f
buildah-tests-1.41.8-1.el10_1.s390x.rpm SHA-256: 54f199a1ad5e6994eeb69e9efc6b3054d597521b17191867cf4f60a44448c02c
buildah-tests-debuginfo-1.41.8-1.el10_1.s390x.rpm SHA-256: 9470a52c2c5785282b6a9c22f7419a70b8ac8f2acdcc870590276cbb75e36993

Red Hat Enterprise Linux for Power, little endian 10

SRPM
buildah-1.41.8-1.el10_1.src.rpm SHA-256: cde36d0478749903ccc62630a2b49bc09f43840eb3134b2df733a1cd5978256c
ppc64le
buildah-1.41.8-1.el10_1.ppc64le.rpm SHA-256: 1cde9371ee795ffd14271dae0ef940676a1f1f86deef370d175aecfb456fd8fc
buildah-debuginfo-1.41.8-1.el10_1.ppc64le.rpm SHA-256: 36e8bdb1694cb2b2987e12bb45887e90402fc81d45f328f6ce1d51778419c524
buildah-debugsource-1.41.8-1.el10_1.ppc64le.rpm SHA-256: 1aa7bd8bdcc66a0401848d7e3b541dfc3902d37ee3008d03a6b00249ef109a11
buildah-tests-1.41.8-1.el10_1.ppc64le.rpm SHA-256: 91a62262b54229a046fda4b2fb9029adc073315281ed742d8fa028f7b9508696
buildah-tests-debuginfo-1.41.8-1.el10_1.ppc64le.rpm SHA-256: ae95fc7b0a4ded3081c29ab840c7fb5a1d643cba8daf6fd64e908f620b2ab0cd

Red Hat Enterprise Linux for ARM 64 10

SRPM
buildah-1.41.8-1.el10_1.src.rpm SHA-256: cde36d0478749903ccc62630a2b49bc09f43840eb3134b2df733a1cd5978256c
aarch64
buildah-1.41.8-1.el10_1.aarch64.rpm SHA-256: 00d10d0f8a75fd3f40324a1d5e8da3a4ee096bc19e2fc8f954a0bee4fb5460ca
buildah-debuginfo-1.41.8-1.el10_1.aarch64.rpm SHA-256: ad47c8c675a44db9f6cd7d5ff480dc3fa169fad47c6b85796ab845b149573f20
buildah-debugsource-1.41.8-1.el10_1.aarch64.rpm SHA-256: 227c377b1c9ac12ab5ae11f19ee7a710ed6d14e208cbd6c35b03d0ecb0d82b06
buildah-tests-1.41.8-1.el10_1.aarch64.rpm SHA-256: a36c58f48ad691408ecf6870da1242ecf055706a3725bd283e40fb34c22a91b6
buildah-tests-debuginfo-1.41.8-1.el10_1.aarch64.rpm SHA-256: 2eb6d58cc15ca8599eca9b6fb20ee6a783aff8cbda9987428fb630b6d2e2052d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility