Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:1025 - Security Advisory
Issued:
2026-01-22
Updated:
2026-01-22

RHSA-2026:1025 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: osbuild-composer security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, and Red Hat Enterprise Linux 8.6 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.6 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64

Fixes

  • BZ - 2407258 - CVE-2025-58183 golang: archive/tar: Unbounded allocation when parsing GNU sparse map

CVEs

  • CVE-2025-58183

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6

SRPM
osbuild-composer-46.3-4.el8_6.src.rpm SHA-256: fbafd44b3d6070a3581bd1772e5eaf334f6f26b59daea34c0890a63215178d25
x86_64
osbuild-composer-46.3-4.el8_6.x86_64.rpm SHA-256: ec1a098ad1128f08e990db00cedb1179e14b8026adcfb1b7a69a0318f489c88a
osbuild-composer-core-46.3-4.el8_6.x86_64.rpm SHA-256: 9618043f74946a51a4aadcf229075a72b0f0f313e7c7334f3901a26c4e2e6055
osbuild-composer-core-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: 30dc6d1c2bfe59888ff7932eab980d49b80fe097294586f31a1bde59b17217bd
osbuild-composer-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: e0b4fcf47b32e86c14ebfff5e816ba77ac45dd7d8896e7f29bd7d56465eb7fbe
osbuild-composer-debugsource-46.3-4.el8_6.x86_64.rpm SHA-256: d4742652fd7b84a0989329794c974a55b80f1c1e48f363e538ebd10feb4a28c8
osbuild-composer-dnf-json-46.3-4.el8_6.x86_64.rpm SHA-256: f2220a468370320077e693fb1dcdadf9d4cd1eaba87b4b3eaa93c9a5710d3862
osbuild-composer-tests-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: 902bf4c7add200594e1c52fd1f125453fe7fd70b8687b2a34e4107514619326f
osbuild-composer-worker-46.3-4.el8_6.x86_64.rpm SHA-256: 5c26f1db744040b2516b3e23d307457f12d286a4b3c1bba67940785b193a9eb7
osbuild-composer-worker-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: c3eaacca8b77d25c6ddb8610f02d083379307a3a455abd52be965d2b20db7783

Red Hat Enterprise Linux Server - AUS 8.6

SRPM
osbuild-composer-46.3-4.el8_6.src.rpm SHA-256: fbafd44b3d6070a3581bd1772e5eaf334f6f26b59daea34c0890a63215178d25
x86_64
osbuild-composer-46.3-4.el8_6.x86_64.rpm SHA-256: ec1a098ad1128f08e990db00cedb1179e14b8026adcfb1b7a69a0318f489c88a
osbuild-composer-core-46.3-4.el8_6.x86_64.rpm SHA-256: 9618043f74946a51a4aadcf229075a72b0f0f313e7c7334f3901a26c4e2e6055
osbuild-composer-core-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: 30dc6d1c2bfe59888ff7932eab980d49b80fe097294586f31a1bde59b17217bd
osbuild-composer-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: e0b4fcf47b32e86c14ebfff5e816ba77ac45dd7d8896e7f29bd7d56465eb7fbe
osbuild-composer-debugsource-46.3-4.el8_6.x86_64.rpm SHA-256: d4742652fd7b84a0989329794c974a55b80f1c1e48f363e538ebd10feb4a28c8
osbuild-composer-dnf-json-46.3-4.el8_6.x86_64.rpm SHA-256: f2220a468370320077e693fb1dcdadf9d4cd1eaba87b4b3eaa93c9a5710d3862
osbuild-composer-tests-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: 902bf4c7add200594e1c52fd1f125453fe7fd70b8687b2a34e4107514619326f
osbuild-composer-worker-46.3-4.el8_6.x86_64.rpm SHA-256: 5c26f1db744040b2516b3e23d307457f12d286a4b3c1bba67940785b193a9eb7
osbuild-composer-worker-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: c3eaacca8b77d25c6ddb8610f02d083379307a3a455abd52be965d2b20db7783

Red Hat Enterprise Linux Server - TUS 8.6

SRPM
osbuild-composer-46.3-4.el8_6.src.rpm SHA-256: fbafd44b3d6070a3581bd1772e5eaf334f6f26b59daea34c0890a63215178d25
x86_64
osbuild-composer-46.3-4.el8_6.x86_64.rpm SHA-256: ec1a098ad1128f08e990db00cedb1179e14b8026adcfb1b7a69a0318f489c88a
osbuild-composer-core-46.3-4.el8_6.x86_64.rpm SHA-256: 9618043f74946a51a4aadcf229075a72b0f0f313e7c7334f3901a26c4e2e6055
osbuild-composer-core-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: 30dc6d1c2bfe59888ff7932eab980d49b80fe097294586f31a1bde59b17217bd
osbuild-composer-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: e0b4fcf47b32e86c14ebfff5e816ba77ac45dd7d8896e7f29bd7d56465eb7fbe
osbuild-composer-debugsource-46.3-4.el8_6.x86_64.rpm SHA-256: d4742652fd7b84a0989329794c974a55b80f1c1e48f363e538ebd10feb4a28c8
osbuild-composer-dnf-json-46.3-4.el8_6.x86_64.rpm SHA-256: f2220a468370320077e693fb1dcdadf9d4cd1eaba87b4b3eaa93c9a5710d3862
osbuild-composer-tests-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: 902bf4c7add200594e1c52fd1f125453fe7fd70b8687b2a34e4107514619326f
osbuild-composer-worker-46.3-4.el8_6.x86_64.rpm SHA-256: 5c26f1db744040b2516b3e23d307457f12d286a4b3c1bba67940785b193a9eb7
osbuild-composer-worker-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: c3eaacca8b77d25c6ddb8610f02d083379307a3a455abd52be965d2b20db7783

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6

SRPM
osbuild-composer-46.3-4.el8_6.src.rpm SHA-256: fbafd44b3d6070a3581bd1772e5eaf334f6f26b59daea34c0890a63215178d25
ppc64le
osbuild-composer-46.3-4.el8_6.ppc64le.rpm SHA-256: be99c7f7350442fd009d3a3fb75180f34d991a10985e476e07456b3d9efb6854
osbuild-composer-core-46.3-4.el8_6.ppc64le.rpm SHA-256: 921a0d095ed6666ec30d0ee6c096a7cb2977b986c856cdb368f31574670cee38
osbuild-composer-core-debuginfo-46.3-4.el8_6.ppc64le.rpm SHA-256: 41c3038bedde76d2f7092961d2789b07ea2cefe40f3846debebd6df19cb9fe7f
osbuild-composer-debuginfo-46.3-4.el8_6.ppc64le.rpm SHA-256: be65d78cb5fc93fd7ef3786ecc0c9184ab791a9097429060e1b45db3e3c0e83b
osbuild-composer-debugsource-46.3-4.el8_6.ppc64le.rpm SHA-256: d839cff74f1d55068f2beb6c31553148cb57ad78cbc9800d8d222033ae6ad992
osbuild-composer-dnf-json-46.3-4.el8_6.ppc64le.rpm SHA-256: 5d1e208fd797df3a732c1d62406e6d136d11b177f343586ba10a801598db5049
osbuild-composer-tests-debuginfo-46.3-4.el8_6.ppc64le.rpm SHA-256: bce5def9908ca4bd54b87409c232df7baaa87020fe4be8ffe9984a33782f4efb
osbuild-composer-worker-46.3-4.el8_6.ppc64le.rpm SHA-256: 22aff8fb5226429f407abdd26b4502e81191b460815e7e9febdeaa4c619924d5
osbuild-composer-worker-debuginfo-46.3-4.el8_6.ppc64le.rpm SHA-256: bf1b3b6ea5ce13f31fee69f4e63ba2f33af583f0eb9364b5dfc7fc35e3c15878

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6

SRPM
osbuild-composer-46.3-4.el8_6.src.rpm SHA-256: fbafd44b3d6070a3581bd1772e5eaf334f6f26b59daea34c0890a63215178d25
x86_64
osbuild-composer-46.3-4.el8_6.x86_64.rpm SHA-256: ec1a098ad1128f08e990db00cedb1179e14b8026adcfb1b7a69a0318f489c88a
osbuild-composer-core-46.3-4.el8_6.x86_64.rpm SHA-256: 9618043f74946a51a4aadcf229075a72b0f0f313e7c7334f3901a26c4e2e6055
osbuild-composer-core-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: 30dc6d1c2bfe59888ff7932eab980d49b80fe097294586f31a1bde59b17217bd
osbuild-composer-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: e0b4fcf47b32e86c14ebfff5e816ba77ac45dd7d8896e7f29bd7d56465eb7fbe
osbuild-composer-debugsource-46.3-4.el8_6.x86_64.rpm SHA-256: d4742652fd7b84a0989329794c974a55b80f1c1e48f363e538ebd10feb4a28c8
osbuild-composer-dnf-json-46.3-4.el8_6.x86_64.rpm SHA-256: f2220a468370320077e693fb1dcdadf9d4cd1eaba87b4b3eaa93c9a5710d3862
osbuild-composer-tests-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: 902bf4c7add200594e1c52fd1f125453fe7fd70b8687b2a34e4107514619326f
osbuild-composer-worker-46.3-4.el8_6.x86_64.rpm SHA-256: 5c26f1db744040b2516b3e23d307457f12d286a4b3c1bba67940785b193a9eb7
osbuild-composer-worker-debuginfo-46.3-4.el8_6.x86_64.rpm SHA-256: c3eaacca8b77d25c6ddb8610f02d083379307a3a455abd52be965d2b20db7783

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility