Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:2124 - Security Advisory
发布:
2026-02-05
已更新:
2026-02-05

RHSA-2026:2124 - Security Advisory

  • 概述
  • 更新的软件包

概述

Important: osbuild-composer security update

类型/严重性

Security Advisory: Important

Red Hat Lightspeed patch analysis

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

修复

  • BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate

CVE

  • CVE-2025-61729

参考

  • https://access.redhat.com/security/updates/classification/#important
注:: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux for x86_64 8

SRPM
osbuild-composer-101.4-3.el8_10.src.rpm SHA-256: 81e260817bd03834ba5e511f8286a87665c4db3ddd39b74a2e8934484fa9eb5b
x86_64
osbuild-composer-101.4-3.el8_10.x86_64.rpm SHA-256: a575e752e910ffe7946f89f7881f122fa6e814414fe18901602f8c04807ef26e
osbuild-composer-core-101.4-3.el8_10.x86_64.rpm SHA-256: 4f5d15709b2f05a4d592a0df7e5f9e99e85b0bf8c1cfa3d488c1967c385a9ef7
osbuild-composer-core-debuginfo-101.4-3.el8_10.x86_64.rpm SHA-256: 9162bef4957853dafb9a6de269ac1778dbaed110b961d500a570f4befa7b8df0
osbuild-composer-debuginfo-101.4-3.el8_10.x86_64.rpm SHA-256: a9ccb71caffdc4dc02d5ad774e4671d284e75a2829fe04ca537d50ca29fe17fa
osbuild-composer-debugsource-101.4-3.el8_10.x86_64.rpm SHA-256: 36fe6d2ae36b542b154454e64babb3411816dd5cddc34fa1930324ba34d8de57
osbuild-composer-tests-debuginfo-101.4-3.el8_10.x86_64.rpm SHA-256: 3638bc342bc15eb84017f57a25b61d3246b029f9690a18f64111ef2d9d017dc6
osbuild-composer-worker-101.4-3.el8_10.x86_64.rpm SHA-256: 4ad4f60ba2791ed734af63c1fba98cdae555e58c6cbc7a7a6d28e1d2668385ce
osbuild-composer-worker-debuginfo-101.4-3.el8_10.x86_64.rpm SHA-256: 4973c9798c3f2a5865a3c699729562dc3d059cc0e3634f72616def11775b849c

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
osbuild-composer-101.4-3.el8_10.src.rpm SHA-256: 81e260817bd03834ba5e511f8286a87665c4db3ddd39b74a2e8934484fa9eb5b
s390x
osbuild-composer-101.4-3.el8_10.s390x.rpm SHA-256: 5e0ff97afbf5b0b6b8289eb37c5953f063b6ab11b8b2616c4d2d1a2d9fb49f73
osbuild-composer-core-101.4-3.el8_10.s390x.rpm SHA-256: e9bf3f93a8308259b35825494290735724acb4655e9c846c3dd1d4556d4c880b
osbuild-composer-core-debuginfo-101.4-3.el8_10.s390x.rpm SHA-256: 9e39f88fa3546c67e1f1fbfe634dfcba9486f3c3564b0d09f99b56b807ab98ed
osbuild-composer-debuginfo-101.4-3.el8_10.s390x.rpm SHA-256: f30cf0c8b3498c742a225478dedd0179a6450b6d7b0db188b0c5ef00b6fc41b7
osbuild-composer-debugsource-101.4-3.el8_10.s390x.rpm SHA-256: e447957c36fa1f586aecb3a1beaa75480acc17cc95bff91e9171f4ee55a6119a
osbuild-composer-tests-debuginfo-101.4-3.el8_10.s390x.rpm SHA-256: b719f88519c5a9a9f1fa0fd1f9b3bd293fd0037519de4f73aeb0a0efa45fecf7
osbuild-composer-worker-101.4-3.el8_10.s390x.rpm SHA-256: 976149182cc42abaa402eaf8d7cb56d690fc58c7bcbf5cb3a248d16063f93188
osbuild-composer-worker-debuginfo-101.4-3.el8_10.s390x.rpm SHA-256: ff8da1e183b970cc4baccc1d41ce90dda078f4542cc0c7ab14d25552e27ca4bd

Red Hat Enterprise Linux for Power, little endian 8

SRPM
osbuild-composer-101.4-3.el8_10.src.rpm SHA-256: 81e260817bd03834ba5e511f8286a87665c4db3ddd39b74a2e8934484fa9eb5b
ppc64le
osbuild-composer-101.4-3.el8_10.ppc64le.rpm SHA-256: 1632d66d8b2609175087400f64f2ceee04a407fc846a91d2f2d23b1683a7aabd
osbuild-composer-core-101.4-3.el8_10.ppc64le.rpm SHA-256: 852bae34d1d2fb39904783e49231ac5de1a9b5d111b52115f4a3a40eea5a5f08
osbuild-composer-core-debuginfo-101.4-3.el8_10.ppc64le.rpm SHA-256: 56606461bc15bfc7c5c17c3deec3c63ff11c943544dca71f7524614957215708
osbuild-composer-debuginfo-101.4-3.el8_10.ppc64le.rpm SHA-256: 64137bec20377b591e2dbd632e137799a482db48492663bb4106f0eae41f1a66
osbuild-composer-debugsource-101.4-3.el8_10.ppc64le.rpm SHA-256: d5beccb7140379201f9fdb78748ea8b546f1e7bbf2a9315d17a3ae8a1ccde0af
osbuild-composer-tests-debuginfo-101.4-3.el8_10.ppc64le.rpm SHA-256: c5a8fdb0a56cced2a94e82fa27d53a597f8b52ad69005bb1e94ce3f6eeff66e8
osbuild-composer-worker-101.4-3.el8_10.ppc64le.rpm SHA-256: 98f987418920bb1ae976124826bf780b9cb2038fca57d79b4a830d78aeaf8c0f
osbuild-composer-worker-debuginfo-101.4-3.el8_10.ppc64le.rpm SHA-256: 70ed527940e7f1de9cbf179c74d52143a8a828a5900de14bbe0b93ea0580d4a6

Red Hat Enterprise Linux for ARM 64 8

SRPM
osbuild-composer-101.4-3.el8_10.src.rpm SHA-256: 81e260817bd03834ba5e511f8286a87665c4db3ddd39b74a2e8934484fa9eb5b
aarch64
osbuild-composer-101.4-3.el8_10.aarch64.rpm SHA-256: 5e4debd3d353a08348183b0e7611e3076cc27705518266e2da23ff6ed0df5bae
osbuild-composer-core-101.4-3.el8_10.aarch64.rpm SHA-256: c77c84083538d10efa3ecab4b6e268b3055e25506a6a40972298dd847360ff01
osbuild-composer-core-debuginfo-101.4-3.el8_10.aarch64.rpm SHA-256: 9ce3adc3c9a0af7ad7309376f5240703689cd00f94127b1e99b4d6c3e3ca4b76
osbuild-composer-debuginfo-101.4-3.el8_10.aarch64.rpm SHA-256: 9b33398b775947aa2ace926866dcb671a540582663353e96542ef82f0c80e424
osbuild-composer-debugsource-101.4-3.el8_10.aarch64.rpm SHA-256: 636fcaed15b7d4b4986331297a4c9ec16190408d8831e8d528fdf262f8f23cb3
osbuild-composer-tests-debuginfo-101.4-3.el8_10.aarch64.rpm SHA-256: d71cd1a11a3e7cac2e9c76485db0eddb41ba8be1071301b906c63270536d4ac3
osbuild-composer-worker-101.4-3.el8_10.aarch64.rpm SHA-256: 11f6b077cf9457214a887327e39c8b0adf96bf7efc563fc953a9d160a6e51f6e
osbuild-composer-worker-debuginfo-101.4-3.el8_10.aarch64.rpm SHA-256: 06f6931add3240f619c6f4e4067f82790c3d434b6a6be345557b7085d1f0a950

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility