Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:1378 - Security Advisory
Issued:
2026-01-27
Updated:
2026-01-27

RHSA-2026:1378 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: osbuild-composer security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64

Fixes

  • BZ - 2407258 - CVE-2025-58183 golang: archive/tar: Unbounded allocation when parsing GNU sparse map

CVEs

  • CVE-2025-58183

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-4.el10_0.src.rpm SHA-256: 5c3ef260b37e813a7eeeca72ef36c423b41c74888fc74cc75a25d7a27e067b6e
x86_64
osbuild-composer-134.1-4.el10_0.x86_64.rpm SHA-256: 201c412a8aa99f51f1b9b3bc2e78367f1d9c8b9990ba36e60c2850c515566b08
osbuild-composer-core-134.1-4.el10_0.x86_64.rpm SHA-256: 56aa1b862e502f2992c92711c00e15a289b937153bd8098a19dddd144266bbc3
osbuild-composer-core-debuginfo-134.1-4.el10_0.x86_64.rpm SHA-256: 0dc35a0408563fa8f86eeb30787b47445f9060d985fa3efac8f08275142a7cea
osbuild-composer-debugsource-134.1-4.el10_0.x86_64.rpm SHA-256: 93a1050476b562baadc5e7cc4a08c26ed7a69c0bcfb24157fd4532eafc19e18d
osbuild-composer-tests-debuginfo-134.1-4.el10_0.x86_64.rpm SHA-256: 6449e5949aae4f4f9c388a8a0a8a374646f9a650602f546df3ac5a298ec7c39b
osbuild-composer-worker-134.1-4.el10_0.x86_64.rpm SHA-256: 117f01ba4889f417e3ad1ba00e9fedc6cb2a3c28583daaa3c97064440c7c1ca1
osbuild-composer-worker-debuginfo-134.1-4.el10_0.x86_64.rpm SHA-256: 4cd5ff7f0a09f1fc330b0fd6ad92931f6114fc7c46a14feb49b02885b10f6170

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-4.el10_0.src.rpm SHA-256: 5c3ef260b37e813a7eeeca72ef36c423b41c74888fc74cc75a25d7a27e067b6e
s390x
osbuild-composer-134.1-4.el10_0.s390x.rpm SHA-256: 80e9da769e987e9cdf44db7c80876205d775f9ff80ec3405ab0178318fbb9990
osbuild-composer-core-134.1-4.el10_0.s390x.rpm SHA-256: 26ec388d580e8b6c4d9aef1d0ef98d5b6bb9a21bd3ffaefd30221b63be3bf32f
osbuild-composer-core-debuginfo-134.1-4.el10_0.s390x.rpm SHA-256: 9042ba5bed489bd8b99a9ffa4d87096da4c5ebf8687a5ae488a56f4ac6deb7e9
osbuild-composer-debugsource-134.1-4.el10_0.s390x.rpm SHA-256: 677f3c91958f116fee66214372c708199408cca50c3d217f0aac3b290b38e1e1
osbuild-composer-tests-debuginfo-134.1-4.el10_0.s390x.rpm SHA-256: 011901f95b11ef479186936107aac579fd1f466be5e8d7fb73ec82536665931a
osbuild-composer-worker-134.1-4.el10_0.s390x.rpm SHA-256: 2c01472530a2c784934bcb68829d123e6f68acbceef6aa6b246dee97215ae084
osbuild-composer-worker-debuginfo-134.1-4.el10_0.s390x.rpm SHA-256: 3ab71933b8ac133613e602a75495571181a6b88e052b4decf5eb3f638ace8013

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-4.el10_0.src.rpm SHA-256: 5c3ef260b37e813a7eeeca72ef36c423b41c74888fc74cc75a25d7a27e067b6e
ppc64le
osbuild-composer-134.1-4.el10_0.ppc64le.rpm SHA-256: 5a83e8f5de92ab1bfac4748cbfea180a2145bf54c33db1651f9b7dd475d38f99
osbuild-composer-core-134.1-4.el10_0.ppc64le.rpm SHA-256: 5590de01057688cce1f8c070d904d3a08d9308420939f61b05d2f5e194066f43
osbuild-composer-core-debuginfo-134.1-4.el10_0.ppc64le.rpm SHA-256: a7af6546752d8dd5070b572eeed40d472634ce3414338eeafc70fb6c9017c2cc
osbuild-composer-debugsource-134.1-4.el10_0.ppc64le.rpm SHA-256: 53309a49863a82ad42ccdc6962edbe1b7fa264d548f0ba2d75210c1d4fc78c53
osbuild-composer-tests-debuginfo-134.1-4.el10_0.ppc64le.rpm SHA-256: 60e3090e333f01a550c44a5044f4bbe538c90986d12b0a4accd96103f184b100
osbuild-composer-worker-134.1-4.el10_0.ppc64le.rpm SHA-256: 028deed1e010d09e15c1a9aac24aa8943af34ea22d464f537a05ad58885a1fc3
osbuild-composer-worker-debuginfo-134.1-4.el10_0.ppc64le.rpm SHA-256: 5b32b3e1b96f61ed9334ee925e803d7dcf36d471bb7e06811cabaacf13126881

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-4.el10_0.src.rpm SHA-256: 5c3ef260b37e813a7eeeca72ef36c423b41c74888fc74cc75a25d7a27e067b6e
aarch64
osbuild-composer-134.1-4.el10_0.aarch64.rpm SHA-256: 8ebba3546f98143627b6490d6f10fbfcfaf08c859a1dc46ab1fd5b4c2669b261
osbuild-composer-core-134.1-4.el10_0.aarch64.rpm SHA-256: 48d7614ba9272bf49b204517102861f5af633a35b0b5839ed061785e5eb6a84f
osbuild-composer-core-debuginfo-134.1-4.el10_0.aarch64.rpm SHA-256: 2caab8513017033df75b2a48dc718a5b8d097173bbfe3b372c8e158f4b0321f8
osbuild-composer-debugsource-134.1-4.el10_0.aarch64.rpm SHA-256: 95db8637b5c86e0b2bf454d75bd30da18ad39a906aa3ea79d21deb86c7a7eb38
osbuild-composer-tests-debuginfo-134.1-4.el10_0.aarch64.rpm SHA-256: adef66caced3d2a2f40d702b5d82e5ea70446984ea98585aeb3705204a0674bd
osbuild-composer-worker-134.1-4.el10_0.aarch64.rpm SHA-256: ecb07e73cf01ba8d57d2cc49a8799c5e00cea60bbea05c355e0d12eaa947de70
osbuild-composer-worker-debuginfo-134.1-4.el10_0.aarch64.rpm SHA-256: cc0657f75729855a5dc40163c326cb69c3e75e0fa75baa8247624d9016c1664f

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-4.el10_0.src.rpm SHA-256: 5c3ef260b37e813a7eeeca72ef36c423b41c74888fc74cc75a25d7a27e067b6e
aarch64
osbuild-composer-134.1-4.el10_0.aarch64.rpm SHA-256: 8ebba3546f98143627b6490d6f10fbfcfaf08c859a1dc46ab1fd5b4c2669b261
osbuild-composer-core-134.1-4.el10_0.aarch64.rpm SHA-256: 48d7614ba9272bf49b204517102861f5af633a35b0b5839ed061785e5eb6a84f
osbuild-composer-core-debuginfo-134.1-4.el10_0.aarch64.rpm SHA-256: 2caab8513017033df75b2a48dc718a5b8d097173bbfe3b372c8e158f4b0321f8
osbuild-composer-debugsource-134.1-4.el10_0.aarch64.rpm SHA-256: 95db8637b5c86e0b2bf454d75bd30da18ad39a906aa3ea79d21deb86c7a7eb38
osbuild-composer-tests-debuginfo-134.1-4.el10_0.aarch64.rpm SHA-256: adef66caced3d2a2f40d702b5d82e5ea70446984ea98585aeb3705204a0674bd
osbuild-composer-worker-134.1-4.el10_0.aarch64.rpm SHA-256: ecb07e73cf01ba8d57d2cc49a8799c5e00cea60bbea05c355e0d12eaa947de70
osbuild-composer-worker-debuginfo-134.1-4.el10_0.aarch64.rpm SHA-256: cc0657f75729855a5dc40163c326cb69c3e75e0fa75baa8247624d9016c1664f

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-4.el10_0.src.rpm SHA-256: 5c3ef260b37e813a7eeeca72ef36c423b41c74888fc74cc75a25d7a27e067b6e
s390x
osbuild-composer-134.1-4.el10_0.s390x.rpm SHA-256: 80e9da769e987e9cdf44db7c80876205d775f9ff80ec3405ab0178318fbb9990
osbuild-composer-core-134.1-4.el10_0.s390x.rpm SHA-256: 26ec388d580e8b6c4d9aef1d0ef98d5b6bb9a21bd3ffaefd30221b63be3bf32f
osbuild-composer-core-debuginfo-134.1-4.el10_0.s390x.rpm SHA-256: 9042ba5bed489bd8b99a9ffa4d87096da4c5ebf8687a5ae488a56f4ac6deb7e9
osbuild-composer-debugsource-134.1-4.el10_0.s390x.rpm SHA-256: 677f3c91958f116fee66214372c708199408cca50c3d217f0aac3b290b38e1e1
osbuild-composer-tests-debuginfo-134.1-4.el10_0.s390x.rpm SHA-256: 011901f95b11ef479186936107aac579fd1f466be5e8d7fb73ec82536665931a
osbuild-composer-worker-134.1-4.el10_0.s390x.rpm SHA-256: 2c01472530a2c784934bcb68829d123e6f68acbceef6aa6b246dee97215ae084
osbuild-composer-worker-debuginfo-134.1-4.el10_0.s390x.rpm SHA-256: 3ab71933b8ac133613e602a75495571181a6b88e052b4decf5eb3f638ace8013

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0

SRPM
osbuild-composer-134.1-4.el10_0.src.rpm SHA-256: 5c3ef260b37e813a7eeeca72ef36c423b41c74888fc74cc75a25d7a27e067b6e
ppc64le
osbuild-composer-134.1-4.el10_0.ppc64le.rpm SHA-256: 5a83e8f5de92ab1bfac4748cbfea180a2145bf54c33db1651f9b7dd475d38f99
osbuild-composer-core-134.1-4.el10_0.ppc64le.rpm SHA-256: 5590de01057688cce1f8c070d904d3a08d9308420939f61b05d2f5e194066f43
osbuild-composer-core-debuginfo-134.1-4.el10_0.ppc64le.rpm SHA-256: a7af6546752d8dd5070b572eeed40d472634ce3414338eeafc70fb6c9017c2cc
osbuild-composer-debugsource-134.1-4.el10_0.ppc64le.rpm SHA-256: 53309a49863a82ad42ccdc6962edbe1b7fa264d548f0ba2d75210c1d4fc78c53
osbuild-composer-tests-debuginfo-134.1-4.el10_0.ppc64le.rpm SHA-256: 60e3090e333f01a550c44a5044f4bbe538c90986d12b0a4accd96103f184b100
osbuild-composer-worker-134.1-4.el10_0.ppc64le.rpm SHA-256: 028deed1e010d09e15c1a9aac24aa8943af34ea22d464f537a05ad58885a1fc3
osbuild-composer-worker-debuginfo-134.1-4.el10_0.ppc64le.rpm SHA-256: 5b32b3e1b96f61ed9334ee925e803d7dcf36d471bb7e06811cabaacf13126881

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-4.el10_0.src.rpm SHA-256: 5c3ef260b37e813a7eeeca72ef36c423b41c74888fc74cc75a25d7a27e067b6e
x86_64
osbuild-composer-134.1-4.el10_0.x86_64.rpm SHA-256: 201c412a8aa99f51f1b9b3bc2e78367f1d9c8b9990ba36e60c2850c515566b08
osbuild-composer-core-134.1-4.el10_0.x86_64.rpm SHA-256: 56aa1b862e502f2992c92711c00e15a289b937153bd8098a19dddd144266bbc3
osbuild-composer-core-debuginfo-134.1-4.el10_0.x86_64.rpm SHA-256: 0dc35a0408563fa8f86eeb30787b47445f9060d985fa3efac8f08275142a7cea
osbuild-composer-debugsource-134.1-4.el10_0.x86_64.rpm SHA-256: 93a1050476b562baadc5e7cc4a08c26ed7a69c0bcfb24157fd4532eafc19e18d
osbuild-composer-tests-debuginfo-134.1-4.el10_0.x86_64.rpm SHA-256: 6449e5949aae4f4f9c388a8a0a8a374646f9a650602f546df3ac5a298ec7c39b
osbuild-composer-worker-134.1-4.el10_0.x86_64.rpm SHA-256: 117f01ba4889f417e3ad1ba00e9fedc6cb2a3c28583daaa3c97064440c7c1ca1
osbuild-composer-worker-debuginfo-134.1-4.el10_0.x86_64.rpm SHA-256: 4cd5ff7f0a09f1fc330b0fd6ad92931f6114fc7c46a14feb49b02885b10f6170

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility