Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2685 - Security Advisory
Issued:
2026-02-12
Updated:
2026-02-12

RHSA-2026:2685 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: osbuild-composer security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload (CVE-2025-65637)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2418900 - CVE-2025-65637 github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload

CVEs

  • CVE-2025-65637

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8

SRPM
osbuild-composer-75-6.el8_8.src.rpm SHA-256: df69b33c96d84f9d65dcf24d3a9b08fc777f8ba2da02cbf172b85c278cc62d0d
x86_64
osbuild-composer-75-6.el8_8.x86_64.rpm SHA-256: 8dca92b9c813a04b4a7333e97ced1aa2db87c0a33bab307e1a8f6da105cd7c72
osbuild-composer-core-75-6.el8_8.x86_64.rpm SHA-256: 5abd41d9c2c0567cf1c2c70dee4413ffdb4a971cb34718bd8a00d0928d7c54d0
osbuild-composer-core-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 9fcd212a8de66963a8a3508c6269a394b2eec299bf55d8d6dc4cc8c36f2e0208
osbuild-composer-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 1de2864a21c5939e68c51f52556685d7f02ba0465a31eac137687f30ea53442e
osbuild-composer-debugsource-75-6.el8_8.x86_64.rpm SHA-256: 90aeca5f0777bd8f9955bf1eebf88ee546867a62fff37137673f218acab3c2a4
osbuild-composer-dnf-json-75-6.el8_8.x86_64.rpm SHA-256: d4c43d8e7c3c9293718b92c6d10be25767c43634ae6b969ac27ad3c59927a1dc
osbuild-composer-tests-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: b194758bddd96938bea6ce64c98bcad8261c61befed489e6fde6bc2515d668c2
osbuild-composer-worker-75-6.el8_8.x86_64.rpm SHA-256: de644b55a072ecc8ba3a0a8d4395e1b0e58665f21e6625fe7d4778255da245d0
osbuild-composer-worker-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 5f242be47538a977a070e19e85ff8452b73c8d6723118eeab007036b84f1efce

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
osbuild-composer-75-6.el8_8.src.rpm SHA-256: df69b33c96d84f9d65dcf24d3a9b08fc777f8ba2da02cbf172b85c278cc62d0d
x86_64
osbuild-composer-75-6.el8_8.x86_64.rpm SHA-256: 8dca92b9c813a04b4a7333e97ced1aa2db87c0a33bab307e1a8f6da105cd7c72
osbuild-composer-core-75-6.el8_8.x86_64.rpm SHA-256: 5abd41d9c2c0567cf1c2c70dee4413ffdb4a971cb34718bd8a00d0928d7c54d0
osbuild-composer-core-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 9fcd212a8de66963a8a3508c6269a394b2eec299bf55d8d6dc4cc8c36f2e0208
osbuild-composer-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 1de2864a21c5939e68c51f52556685d7f02ba0465a31eac137687f30ea53442e
osbuild-composer-debugsource-75-6.el8_8.x86_64.rpm SHA-256: 90aeca5f0777bd8f9955bf1eebf88ee546867a62fff37137673f218acab3c2a4
osbuild-composer-dnf-json-75-6.el8_8.x86_64.rpm SHA-256: d4c43d8e7c3c9293718b92c6d10be25767c43634ae6b969ac27ad3c59927a1dc
osbuild-composer-tests-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: b194758bddd96938bea6ce64c98bcad8261c61befed489e6fde6bc2515d668c2
osbuild-composer-worker-75-6.el8_8.x86_64.rpm SHA-256: de644b55a072ecc8ba3a0a8d4395e1b0e58665f21e6625fe7d4778255da245d0
osbuild-composer-worker-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 5f242be47538a977a070e19e85ff8452b73c8d6723118eeab007036b84f1efce

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
osbuild-composer-75-6.el8_8.src.rpm SHA-256: df69b33c96d84f9d65dcf24d3a9b08fc777f8ba2da02cbf172b85c278cc62d0d
ppc64le
osbuild-composer-75-6.el8_8.ppc64le.rpm SHA-256: 3ad32b28686b2ac1b95492dc262e421c0f5640fad0e60b0e7cbf823d00dacc25
osbuild-composer-core-75-6.el8_8.ppc64le.rpm SHA-256: ec44d52cfcd0aecd59c2b1c1b7d9ed26b7a123b734f9cd7f6a21d40967fad7f8
osbuild-composer-core-debuginfo-75-6.el8_8.ppc64le.rpm SHA-256: e4689df543ff702fdc33907b3efa101ebd159a0fbe3b9706fa330f94ede785fc
osbuild-composer-debuginfo-75-6.el8_8.ppc64le.rpm SHA-256: bf2093516931e6b424a29688abd790ea475036a86bb42e1ac2e15b48e2d33ce0
osbuild-composer-debugsource-75-6.el8_8.ppc64le.rpm SHA-256: 56e7f3bd6c0f527ec064087fccc79db7a5a50cf50b68fc0cd0cbbc4731dd11f4
osbuild-composer-dnf-json-75-6.el8_8.ppc64le.rpm SHA-256: acc502168d1478cb732285edeb6f769334e7f951a4908361e8b45a760eb87c4b
osbuild-composer-tests-debuginfo-75-6.el8_8.ppc64le.rpm SHA-256: 907d932447f409db8d77889fb48c21e90c2344856f04a1207a8a40719560bd7e
osbuild-composer-worker-75-6.el8_8.ppc64le.rpm SHA-256: 9bae2b073c6d2184eb4d1a7d275453912643e30c8788a869461a65adaa878750
osbuild-composer-worker-debuginfo-75-6.el8_8.ppc64le.rpm SHA-256: 182f28bf40512e4a314537aef9fa0b4131e2bfffa1f4145d68437003e2b41399

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
osbuild-composer-75-6.el8_8.src.rpm SHA-256: df69b33c96d84f9d65dcf24d3a9b08fc777f8ba2da02cbf172b85c278cc62d0d
x86_64
osbuild-composer-75-6.el8_8.x86_64.rpm SHA-256: 8dca92b9c813a04b4a7333e97ced1aa2db87c0a33bab307e1a8f6da105cd7c72
osbuild-composer-core-75-6.el8_8.x86_64.rpm SHA-256: 5abd41d9c2c0567cf1c2c70dee4413ffdb4a971cb34718bd8a00d0928d7c54d0
osbuild-composer-core-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 9fcd212a8de66963a8a3508c6269a394b2eec299bf55d8d6dc4cc8c36f2e0208
osbuild-composer-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 1de2864a21c5939e68c51f52556685d7f02ba0465a31eac137687f30ea53442e
osbuild-composer-debugsource-75-6.el8_8.x86_64.rpm SHA-256: 90aeca5f0777bd8f9955bf1eebf88ee546867a62fff37137673f218acab3c2a4
osbuild-composer-dnf-json-75-6.el8_8.x86_64.rpm SHA-256: d4c43d8e7c3c9293718b92c6d10be25767c43634ae6b969ac27ad3c59927a1dc
osbuild-composer-tests-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: b194758bddd96938bea6ce64c98bcad8261c61befed489e6fde6bc2515d668c2
osbuild-composer-worker-75-6.el8_8.x86_64.rpm SHA-256: de644b55a072ecc8ba3a0a8d4395e1b0e58665f21e6625fe7d4778255da245d0
osbuild-composer-worker-debuginfo-75-6.el8_8.x86_64.rpm SHA-256: 5f242be47538a977a070e19e85ff8452b73c8d6723118eeab007036b84f1efce

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility