Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:0437 - Security Advisory
发布:
2026-01-12
已更新:
2026-01-12

RHSA-2026:0437 - Security Advisory

  • 概述
  • 更新的软件包

概述

Important: buildah security update

类型/严重性

Security Advisory: Important

Red Hat Lightspeed patch analysis

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for buildah is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

修复

  • BZ - 2414943 - CVE-2025-47913 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS

CVE

  • CVE-2025-47913

参考

  • https://access.redhat.com/security/updates/classification/#important
注:: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux for x86_64 9

SRPM
buildah-1.41.8-1.el9_7.src.rpm SHA-256: 3768d3a29c0acc02aa1bf7af1c80ea0d761ff4c0cf66c8ebc3345206de273183
x86_64
buildah-1.41.8-1.el9_7.x86_64.rpm SHA-256: 7c541a1aaf7a6465430d0589c6ca9de4cc7a5741d7553c3809ece953f2977c37
buildah-debuginfo-1.41.8-1.el9_7.x86_64.rpm SHA-256: fbe9c3dec586ac4f523a2fec22bea715cfd220c49dd7b6b834776ca578a35aba
buildah-debugsource-1.41.8-1.el9_7.x86_64.rpm SHA-256: 584990ac4aac04e0d1b714ff236ff10858500f558ad9fb2614de5a157af4edef
buildah-tests-1.41.8-1.el9_7.x86_64.rpm SHA-256: cd529093d4404ae0d009e7a8c28d501ea63494cf87e17e1668e4b402dbed207d
buildah-tests-debuginfo-1.41.8-1.el9_7.x86_64.rpm SHA-256: 335c7fd3f0f0f58bd433cf34085f10b030446245798c293def385569a16994d1

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
buildah-1.41.8-1.el9_7.src.rpm SHA-256: 3768d3a29c0acc02aa1bf7af1c80ea0d761ff4c0cf66c8ebc3345206de273183
s390x
buildah-1.41.8-1.el9_7.s390x.rpm SHA-256: 690a1533452ccdb7e5d589c89c62aa0a5d23fec5736ab522256ca6b081ef6ccb
buildah-debuginfo-1.41.8-1.el9_7.s390x.rpm SHA-256: bfe6304a212e24274998d51b6813fd7b271c5025a428fd82af9953172c832e60
buildah-debugsource-1.41.8-1.el9_7.s390x.rpm SHA-256: 5b7672bdf1e2afae595054d76b7d34803e624105ad16b4df9c6fab9fc44993da
buildah-tests-1.41.8-1.el9_7.s390x.rpm SHA-256: 7627987a06878fc4f9ee247dbd79ba1318b607130d2a107e7c40ad9b9516271f
buildah-tests-debuginfo-1.41.8-1.el9_7.s390x.rpm SHA-256: afec15023dff183d0a32559e40ce55da75005394587cc5071f05cb9cb3d3e5c5

Red Hat Enterprise Linux for Power, little endian 9

SRPM
buildah-1.41.8-1.el9_7.src.rpm SHA-256: 3768d3a29c0acc02aa1bf7af1c80ea0d761ff4c0cf66c8ebc3345206de273183
ppc64le
buildah-1.41.8-1.el9_7.ppc64le.rpm SHA-256: 183d9b8dff892ec852249ea4524683e9ff1476fc20a85fe1f917fd4c77a4dd2f
buildah-debuginfo-1.41.8-1.el9_7.ppc64le.rpm SHA-256: 5091576b193bb86320f2cec0479b643828d9e6429848d056b8f6b62cb0b33a03
buildah-debugsource-1.41.8-1.el9_7.ppc64le.rpm SHA-256: b931b569e242e16b2e682a82b569674b884b825f78677daa27d602f4d033af60
buildah-tests-1.41.8-1.el9_7.ppc64le.rpm SHA-256: b080573f5970b6a93dee8f508b2882ab4c8b47d150ae628b3dfc3295d913f51b
buildah-tests-debuginfo-1.41.8-1.el9_7.ppc64le.rpm SHA-256: 13efbaecda37475080097c2f79c4c67318baef83d4f13a4aea424a2a816fca48

Red Hat Enterprise Linux for ARM 64 9

SRPM
buildah-1.41.8-1.el9_7.src.rpm SHA-256: 3768d3a29c0acc02aa1bf7af1c80ea0d761ff4c0cf66c8ebc3345206de273183
aarch64
buildah-1.41.8-1.el9_7.aarch64.rpm SHA-256: 624758c2d4668ece1dde58e006613206fcf8341705e9aa1b53799673d7b4db60
buildah-debuginfo-1.41.8-1.el9_7.aarch64.rpm SHA-256: 92ca19d0480dff392aaaee1228f48fa7b3007fcc6d3f102d0b7f60e816d7b5c3
buildah-debugsource-1.41.8-1.el9_7.aarch64.rpm SHA-256: b15c19794db38f2412387ec70d8e56a1f8db51e1566eeb6dd1068edae095ba47
buildah-tests-1.41.8-1.el9_7.aarch64.rpm SHA-256: 1e78e6458854b0dad9e3d99ad21bfd81f177b367fce048c12d33c075ecf66801
buildah-tests-debuginfo-1.41.8-1.el9_7.aarch64.rpm SHA-256: 6718e5005b9527ed640d011de1748cb84e25f5d8d55468871da15321264b1cdb

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility