Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:1380 - Security Advisory
发布:
2026-01-27
已更新:
2026-01-27

RHSA-2026:1380 - Security Advisory

  • 概述
  • 更新的软件包

概述

Moderate: osbuild-composer security update

类型/严重性

Security Advisory: Moderate

Red Hat Insights 补丁分析

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x

修复

  • BZ - 2407258 - CVE-2025-58183 golang: archive/tar: Unbounded allocation when parsing GNU sparse map

CVE

  • CVE-2025-58183

参考

  • https://access.redhat.com/security/updates/classification/#moderate
备注: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux for x86_64 8

SRPM
osbuild-composer-101.4-2.el8_10.src.rpm SHA-256: 62c6f11fad52bf19460a5773b00f040e4264da1acb9035126d880edc12256245
x86_64
osbuild-composer-101.4-2.el8_10.x86_64.rpm SHA-256: 033d047085db22a66727dbd5f89d24cfe5093cf237e1413b3d0475a553ced384
osbuild-composer-core-101.4-2.el8_10.x86_64.rpm SHA-256: b3e2ebffb8eb28e32f15087b1c0d68e6f5e7ac7e777c645beb1973322c1526cd
osbuild-composer-core-debuginfo-101.4-2.el8_10.x86_64.rpm SHA-256: 52ecbff71843ec6d1c425009ff494d85120bc8573881e7351de9dda811e68f68
osbuild-composer-debuginfo-101.4-2.el8_10.x86_64.rpm SHA-256: 9e9af9e43584589bb877345fce7efb6a6e55b56e070086ed75f1148c6bd903f5
osbuild-composer-debugsource-101.4-2.el8_10.x86_64.rpm SHA-256: e2d0de789dcb0e89eb95409d9a99a1b2b22de02716361b79ccdc13b68eb827bf
osbuild-composer-tests-debuginfo-101.4-2.el8_10.x86_64.rpm SHA-256: 2def513d7ed3e779f3d15e4634bc67b0688b5537de879245991ad041afcfa8a9
osbuild-composer-worker-101.4-2.el8_10.x86_64.rpm SHA-256: 43bc7da5b66e16cf3b3b4280c2f76121c9cd403ff89b92a8f61bbbedf2b382e8
osbuild-composer-worker-debuginfo-101.4-2.el8_10.x86_64.rpm SHA-256: 0abc485118f2ba50201852b86f2300f03cd6701a9b0465bd1a45415170ce19ff

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
osbuild-composer-101.4-2.el8_10.src.rpm SHA-256: 62c6f11fad52bf19460a5773b00f040e4264da1acb9035126d880edc12256245
s390x
osbuild-composer-101.4-2.el8_10.s390x.rpm SHA-256: 3388dea99c430d6d470c83a40eb807897486abe79d9ca2de4e26b60f4d888dfc
osbuild-composer-core-101.4-2.el8_10.s390x.rpm SHA-256: 68c46d07739e425d84174e9deebb4048f53a34fc3c14558b6f656af7d53b3ea8
osbuild-composer-core-debuginfo-101.4-2.el8_10.s390x.rpm SHA-256: 90114298e01fcec3d57a002b7fc846adfc1e9ac8822f1ceba907cd9c0562e7a5
osbuild-composer-debuginfo-101.4-2.el8_10.s390x.rpm SHA-256: 514409d5087de2e084ae372d0b8dd965ffcdc499194d4d8e56ffa93e966c057e
osbuild-composer-debugsource-101.4-2.el8_10.s390x.rpm SHA-256: d0dcbf95e62d9eae9a4bb984b94fbb73c68594e9d731f0a89c504bb2718776b7
osbuild-composer-tests-debuginfo-101.4-2.el8_10.s390x.rpm SHA-256: 4ac5752f7009e1f29cb0deefbe1ef5c6cc102da1b0ee3b6b52a2a64394bbbbb0
osbuild-composer-worker-101.4-2.el8_10.s390x.rpm SHA-256: 802f60a70a985616d70e32439be7f046447899b196e28240c7da58be257e6afc
osbuild-composer-worker-debuginfo-101.4-2.el8_10.s390x.rpm SHA-256: a10882416092e6b1877dc95bd84c287344879f281ae1bb8ea4e17ada3e78d775

Red Hat Enterprise Linux for Power, little endian 8

SRPM
osbuild-composer-101.4-2.el8_10.src.rpm SHA-256: 62c6f11fad52bf19460a5773b00f040e4264da1acb9035126d880edc12256245
ppc64le
osbuild-composer-101.4-2.el8_10.ppc64le.rpm SHA-256: 95adf84636a9f6236bce1e4fd4d638ac8bf902c09b64255e6b12908d73226800
osbuild-composer-core-101.4-2.el8_10.ppc64le.rpm SHA-256: 7b12e6b538fb8f5f16857dc64e7f70b1133ce59299071f939f6ac9f938596df0
osbuild-composer-core-debuginfo-101.4-2.el8_10.ppc64le.rpm SHA-256: 75345165fbfd4871d83623f7eb0d3aeff2af41ca3ae73a04aac6d0ba78ef5ec5
osbuild-composer-debuginfo-101.4-2.el8_10.ppc64le.rpm SHA-256: df84cecf4a505b54b3438b7775330b71a70c3b56556d5216802ac7a5ec592cbd
osbuild-composer-debugsource-101.4-2.el8_10.ppc64le.rpm SHA-256: 289de07e9dfb5642afa17c0a784eda65091ad7b004d18d90228d7bf638955a14
osbuild-composer-tests-debuginfo-101.4-2.el8_10.ppc64le.rpm SHA-256: 2bdcbafebcb755b39fdf36b9eb44d7d67482e2f41ff5c20881366d1d20b2ab04
osbuild-composer-worker-101.4-2.el8_10.ppc64le.rpm SHA-256: dc9e5b86e307e95ae0a7a30dbad335b4e738d7f473dbaae00cc768abffd7a896
osbuild-composer-worker-debuginfo-101.4-2.el8_10.ppc64le.rpm SHA-256: e0d47d05be97cb074d034852a802a0985ea12cbef2439d4193486ab586af29ea

Red Hat Enterprise Linux for ARM 64 8

SRPM
osbuild-composer-101.4-2.el8_10.src.rpm SHA-256: 62c6f11fad52bf19460a5773b00f040e4264da1acb9035126d880edc12256245
aarch64
osbuild-composer-101.4-2.el8_10.aarch64.rpm SHA-256: d54a779f89127e3fcbd5aa770a5d4b145de51db6dbf2dacd317b4a5b5e728f0d
osbuild-composer-core-101.4-2.el8_10.aarch64.rpm SHA-256: 65f316fc51fd46070b1410ecac9a0a8061f70c2e08633112f06f4300edd72606
osbuild-composer-core-debuginfo-101.4-2.el8_10.aarch64.rpm SHA-256: 50e8e7331c0bf0d014472436fae6f3a20ad6671843a1e2e6428dae0d17e59c1a
osbuild-composer-debuginfo-101.4-2.el8_10.aarch64.rpm SHA-256: b9a66394de698e7e931c17ce8fbf561977c417a5e0b3e68309454c23ba7de65b
osbuild-composer-debugsource-101.4-2.el8_10.aarch64.rpm SHA-256: 086a3e4f84c4513097ede4b5e5530ee470fd08600cbe14ac00f2a1b4eb6bb66f
osbuild-composer-tests-debuginfo-101.4-2.el8_10.aarch64.rpm SHA-256: f3a73e5dafe6291db0c354894745b9eb5ab210913da5d526dc1795d702309d15
osbuild-composer-worker-101.4-2.el8_10.aarch64.rpm SHA-256: 02247207a9dbc36b8eab37a01ba6fc816a279a0f0b4f0cfbdc95099086818e97
osbuild-composer-worker-debuginfo-101.4-2.el8_10.aarch64.rpm SHA-256: 5494cff6ae15c6ee1454fed818fcbb6996918087c9e3f0f833aad0c6d513ede8

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.4-2.el8_10.src.rpm SHA-256: 62c6f11fad52bf19460a5773b00f040e4264da1acb9035126d880edc12256245
x86_64
osbuild-composer-101.4-2.el8_10.x86_64.rpm SHA-256: 033d047085db22a66727dbd5f89d24cfe5093cf237e1413b3d0475a553ced384
osbuild-composer-core-101.4-2.el8_10.x86_64.rpm SHA-256: b3e2ebffb8eb28e32f15087b1c0d68e6f5e7ac7e777c645beb1973322c1526cd
osbuild-composer-core-debuginfo-101.4-2.el8_10.x86_64.rpm SHA-256: 52ecbff71843ec6d1c425009ff494d85120bc8573881e7351de9dda811e68f68
osbuild-composer-debuginfo-101.4-2.el8_10.x86_64.rpm SHA-256: 9e9af9e43584589bb877345fce7efb6a6e55b56e070086ed75f1148c6bd903f5
osbuild-composer-debugsource-101.4-2.el8_10.x86_64.rpm SHA-256: e2d0de789dcb0e89eb95409d9a99a1b2b22de02716361b79ccdc13b68eb827bf
osbuild-composer-tests-debuginfo-101.4-2.el8_10.x86_64.rpm SHA-256: 2def513d7ed3e779f3d15e4634bc67b0688b5537de879245991ad041afcfa8a9
osbuild-composer-worker-101.4-2.el8_10.x86_64.rpm SHA-256: 43bc7da5b66e16cf3b3b4280c2f76121c9cd403ff89b92a8f61bbbedf2b382e8
osbuild-composer-worker-debuginfo-101.4-2.el8_10.x86_64.rpm SHA-256: 0abc485118f2ba50201852b86f2300f03cd6701a9b0465bd1a45415170ce19ff

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.4-2.el8_10.src.rpm SHA-256: 62c6f11fad52bf19460a5773b00f040e4264da1acb9035126d880edc12256245
aarch64
osbuild-composer-101.4-2.el8_10.aarch64.rpm SHA-256: d54a779f89127e3fcbd5aa770a5d4b145de51db6dbf2dacd317b4a5b5e728f0d
osbuild-composer-core-101.4-2.el8_10.aarch64.rpm SHA-256: 65f316fc51fd46070b1410ecac9a0a8061f70c2e08633112f06f4300edd72606
osbuild-composer-core-debuginfo-101.4-2.el8_10.aarch64.rpm SHA-256: 50e8e7331c0bf0d014472436fae6f3a20ad6671843a1e2e6428dae0d17e59c1a
osbuild-composer-debuginfo-101.4-2.el8_10.aarch64.rpm SHA-256: b9a66394de698e7e931c17ce8fbf561977c417a5e0b3e68309454c23ba7de65b
osbuild-composer-debugsource-101.4-2.el8_10.aarch64.rpm SHA-256: 086a3e4f84c4513097ede4b5e5530ee470fd08600cbe14ac00f2a1b4eb6bb66f
osbuild-composer-tests-debuginfo-101.4-2.el8_10.aarch64.rpm SHA-256: f3a73e5dafe6291db0c354894745b9eb5ab210913da5d526dc1795d702309d15
osbuild-composer-worker-101.4-2.el8_10.aarch64.rpm SHA-256: 02247207a9dbc36b8eab37a01ba6fc816a279a0f0b4f0cfbdc95099086818e97
osbuild-composer-worker-debuginfo-101.4-2.el8_10.aarch64.rpm SHA-256: 5494cff6ae15c6ee1454fed818fcbb6996918087c9e3f0f833aad0c6d513ede8

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.4-2.el8_10.src.rpm SHA-256: 62c6f11fad52bf19460a5773b00f040e4264da1acb9035126d880edc12256245
ppc64le
osbuild-composer-101.4-2.el8_10.ppc64le.rpm SHA-256: 95adf84636a9f6236bce1e4fd4d638ac8bf902c09b64255e6b12908d73226800
osbuild-composer-core-101.4-2.el8_10.ppc64le.rpm SHA-256: 7b12e6b538fb8f5f16857dc64e7f70b1133ce59299071f939f6ac9f938596df0
osbuild-composer-core-debuginfo-101.4-2.el8_10.ppc64le.rpm SHA-256: 75345165fbfd4871d83623f7eb0d3aeff2af41ca3ae73a04aac6d0ba78ef5ec5
osbuild-composer-debuginfo-101.4-2.el8_10.ppc64le.rpm SHA-256: df84cecf4a505b54b3438b7775330b71a70c3b56556d5216802ac7a5ec592cbd
osbuild-composer-debugsource-101.4-2.el8_10.ppc64le.rpm SHA-256: 289de07e9dfb5642afa17c0a784eda65091ad7b004d18d90228d7bf638955a14
osbuild-composer-tests-debuginfo-101.4-2.el8_10.ppc64le.rpm SHA-256: 2bdcbafebcb755b39fdf36b9eb44d7d67482e2f41ff5c20881366d1d20b2ab04
osbuild-composer-worker-101.4-2.el8_10.ppc64le.rpm SHA-256: dc9e5b86e307e95ae0a7a30dbad335b4e738d7f473dbaae00cc768abffd7a896
osbuild-composer-worker-debuginfo-101.4-2.el8_10.ppc64le.rpm SHA-256: e0d47d05be97cb074d034852a802a0985ea12cbef2439d4193486ab586af29ea

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.4-2.el8_10.src.rpm SHA-256: 62c6f11fad52bf19460a5773b00f040e4264da1acb9035126d880edc12256245
s390x
osbuild-composer-101.4-2.el8_10.s390x.rpm SHA-256: 3388dea99c430d6d470c83a40eb807897486abe79d9ca2de4e26b60f4d888dfc
osbuild-composer-core-101.4-2.el8_10.s390x.rpm SHA-256: 68c46d07739e425d84174e9deebb4048f53a34fc3c14558b6f656af7d53b3ea8
osbuild-composer-core-debuginfo-101.4-2.el8_10.s390x.rpm SHA-256: 90114298e01fcec3d57a002b7fc846adfc1e9ac8822f1ceba907cd9c0562e7a5
osbuild-composer-debuginfo-101.4-2.el8_10.s390x.rpm SHA-256: 514409d5087de2e084ae372d0b8dd965ffcdc499194d4d8e56ffa93e966c057e
osbuild-composer-debugsource-101.4-2.el8_10.s390x.rpm SHA-256: d0dcbf95e62d9eae9a4bb984b94fbb73c68594e9d731f0a89c504bb2718776b7
osbuild-composer-tests-debuginfo-101.4-2.el8_10.s390x.rpm SHA-256: 4ac5752f7009e1f29cb0deefbe1ef5c6cc102da1b0ee3b6b52a2a64394bbbbb0
osbuild-composer-worker-101.4-2.el8_10.s390x.rpm SHA-256: 802f60a70a985616d70e32439be7f046447899b196e28240c7da58be257e6afc
osbuild-composer-worker-debuginfo-101.4-2.el8_10.s390x.rpm SHA-256: a10882416092e6b1877dc95bd84c287344879f281ae1bb8ea4e17ada3e78d775

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility