Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2687 - Security Advisory
Issued:
2026-02-12
Updated:
2026-02-12

RHSA-2026:2687 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: osbuild-composer security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, and Red Hat Enterprise Linux 8.6 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload (CVE-2025-65637)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.6 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64

Fixes

  • BZ - 2418900 - CVE-2025-65637 github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload

CVEs

  • CVE-2025-65637

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6

SRPM
osbuild-composer-46.3-5.el8_6.src.rpm SHA-256: 6691e08dc5e7800299ce0aea8229152c45b716e85dd21f7bc150a02d5dbe464b
x86_64
osbuild-composer-46.3-5.el8_6.x86_64.rpm SHA-256: 4d783d9fb529918ff281d63d820e90f3a5dfe95b2960232e4ed86949040d3d2d
osbuild-composer-core-46.3-5.el8_6.x86_64.rpm SHA-256: 10c0ca2d9f24f3aee87c6376f9e8b395254b606a6fa20f540ab6d742a0836a19
osbuild-composer-core-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: 8f47155d1c9a4c1333536572029e47b58750cf8129cfc4fda72d6cc3451bc119
osbuild-composer-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: 3db06d27bab674233e8259e4ec5f0aa3831e5879c2a70b511ef4c27941e7a8be
osbuild-composer-debugsource-46.3-5.el8_6.x86_64.rpm SHA-256: 8d5e952fa671e0dec402026f75cae65bb4ad8959ffcb92346d33b66912761d25
osbuild-composer-dnf-json-46.3-5.el8_6.x86_64.rpm SHA-256: 51f60b2838f62d68ad9acb47c3ad746004b084cee2854846493d136b7cd3c2ea
osbuild-composer-tests-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: f6aa7ab5fc9459566ab03346f2729d0474f151f97ca30dff3707ad7f261f497f
osbuild-composer-worker-46.3-5.el8_6.x86_64.rpm SHA-256: 1096ee72014c44d0ed3abcca13ef628fe8962d336086004bf07090eca70f5335
osbuild-composer-worker-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: ea04b660684237f4341bb41b33b9df8d5c3c06d136a173949459953ab705600e

Red Hat Enterprise Linux Server - AUS 8.6

SRPM
osbuild-composer-46.3-5.el8_6.src.rpm SHA-256: 6691e08dc5e7800299ce0aea8229152c45b716e85dd21f7bc150a02d5dbe464b
x86_64
osbuild-composer-46.3-5.el8_6.x86_64.rpm SHA-256: 4d783d9fb529918ff281d63d820e90f3a5dfe95b2960232e4ed86949040d3d2d
osbuild-composer-core-46.3-5.el8_6.x86_64.rpm SHA-256: 10c0ca2d9f24f3aee87c6376f9e8b395254b606a6fa20f540ab6d742a0836a19
osbuild-composer-core-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: 8f47155d1c9a4c1333536572029e47b58750cf8129cfc4fda72d6cc3451bc119
osbuild-composer-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: 3db06d27bab674233e8259e4ec5f0aa3831e5879c2a70b511ef4c27941e7a8be
osbuild-composer-debugsource-46.3-5.el8_6.x86_64.rpm SHA-256: 8d5e952fa671e0dec402026f75cae65bb4ad8959ffcb92346d33b66912761d25
osbuild-composer-dnf-json-46.3-5.el8_6.x86_64.rpm SHA-256: 51f60b2838f62d68ad9acb47c3ad746004b084cee2854846493d136b7cd3c2ea
osbuild-composer-tests-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: f6aa7ab5fc9459566ab03346f2729d0474f151f97ca30dff3707ad7f261f497f
osbuild-composer-worker-46.3-5.el8_6.x86_64.rpm SHA-256: 1096ee72014c44d0ed3abcca13ef628fe8962d336086004bf07090eca70f5335
osbuild-composer-worker-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: ea04b660684237f4341bb41b33b9df8d5c3c06d136a173949459953ab705600e

Red Hat Enterprise Linux Server - TUS 8.6

SRPM
osbuild-composer-46.3-5.el8_6.src.rpm SHA-256: 6691e08dc5e7800299ce0aea8229152c45b716e85dd21f7bc150a02d5dbe464b
x86_64
osbuild-composer-46.3-5.el8_6.x86_64.rpm SHA-256: 4d783d9fb529918ff281d63d820e90f3a5dfe95b2960232e4ed86949040d3d2d
osbuild-composer-core-46.3-5.el8_6.x86_64.rpm SHA-256: 10c0ca2d9f24f3aee87c6376f9e8b395254b606a6fa20f540ab6d742a0836a19
osbuild-composer-core-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: 8f47155d1c9a4c1333536572029e47b58750cf8129cfc4fda72d6cc3451bc119
osbuild-composer-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: 3db06d27bab674233e8259e4ec5f0aa3831e5879c2a70b511ef4c27941e7a8be
osbuild-composer-debugsource-46.3-5.el8_6.x86_64.rpm SHA-256: 8d5e952fa671e0dec402026f75cae65bb4ad8959ffcb92346d33b66912761d25
osbuild-composer-dnf-json-46.3-5.el8_6.x86_64.rpm SHA-256: 51f60b2838f62d68ad9acb47c3ad746004b084cee2854846493d136b7cd3c2ea
osbuild-composer-tests-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: f6aa7ab5fc9459566ab03346f2729d0474f151f97ca30dff3707ad7f261f497f
osbuild-composer-worker-46.3-5.el8_6.x86_64.rpm SHA-256: 1096ee72014c44d0ed3abcca13ef628fe8962d336086004bf07090eca70f5335
osbuild-composer-worker-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: ea04b660684237f4341bb41b33b9df8d5c3c06d136a173949459953ab705600e

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6

SRPM
osbuild-composer-46.3-5.el8_6.src.rpm SHA-256: 6691e08dc5e7800299ce0aea8229152c45b716e85dd21f7bc150a02d5dbe464b
ppc64le
osbuild-composer-46.3-5.el8_6.ppc64le.rpm SHA-256: 061670d4f5b66bfabfe73838b185ec90b2e2342f58e65f44361966937542008c
osbuild-composer-core-46.3-5.el8_6.ppc64le.rpm SHA-256: 0013d649c6d0ad2453c4baff3faf1a1325828d8ab81c13af3c317ce98cb1033c
osbuild-composer-core-debuginfo-46.3-5.el8_6.ppc64le.rpm SHA-256: 42ac856bb76327349d307c19048ed0332e931f81348c1d2c24612fbc8aaf6fac
osbuild-composer-debuginfo-46.3-5.el8_6.ppc64le.rpm SHA-256: 95d7642de7e037d64f0fd5e064338ddc653abfa2714a0abce4c7ba0e58d3c3aa
osbuild-composer-debugsource-46.3-5.el8_6.ppc64le.rpm SHA-256: fc6bae0382d994c526cd00870a89605b309c81e3d56d98339d680bee5fbecf0f
osbuild-composer-dnf-json-46.3-5.el8_6.ppc64le.rpm SHA-256: a7b22e0e19ed9ecf7e594a86185561cd696bca30fe1656a6620467809f0c8412
osbuild-composer-tests-debuginfo-46.3-5.el8_6.ppc64le.rpm SHA-256: 1463b36b0f40a3d7743d42a55702c554750521bd8877248b0f184d781204a3c6
osbuild-composer-worker-46.3-5.el8_6.ppc64le.rpm SHA-256: 78e2517a201b01dc7bfa071ffee07b2fdb4bbe99e4b903fc492ee68902feddf3
osbuild-composer-worker-debuginfo-46.3-5.el8_6.ppc64le.rpm SHA-256: 68d97f9ba0fe7ec08f9397e1e5d4077dfe083b4fae0de42286b2e88021dcb4ef

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6

SRPM
osbuild-composer-46.3-5.el8_6.src.rpm SHA-256: 6691e08dc5e7800299ce0aea8229152c45b716e85dd21f7bc150a02d5dbe464b
x86_64
osbuild-composer-46.3-5.el8_6.x86_64.rpm SHA-256: 4d783d9fb529918ff281d63d820e90f3a5dfe95b2960232e4ed86949040d3d2d
osbuild-composer-core-46.3-5.el8_6.x86_64.rpm SHA-256: 10c0ca2d9f24f3aee87c6376f9e8b395254b606a6fa20f540ab6d742a0836a19
osbuild-composer-core-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: 8f47155d1c9a4c1333536572029e47b58750cf8129cfc4fda72d6cc3451bc119
osbuild-composer-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: 3db06d27bab674233e8259e4ec5f0aa3831e5879c2a70b511ef4c27941e7a8be
osbuild-composer-debugsource-46.3-5.el8_6.x86_64.rpm SHA-256: 8d5e952fa671e0dec402026f75cae65bb4ad8959ffcb92346d33b66912761d25
osbuild-composer-dnf-json-46.3-5.el8_6.x86_64.rpm SHA-256: 51f60b2838f62d68ad9acb47c3ad746004b084cee2854846493d136b7cd3c2ea
osbuild-composer-tests-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: f6aa7ab5fc9459566ab03346f2729d0474f151f97ca30dff3707ad7f261f497f
osbuild-composer-worker-46.3-5.el8_6.x86_64.rpm SHA-256: 1096ee72014c44d0ed3abcca13ef628fe8962d336086004bf07090eca70f5335
osbuild-composer-worker-debuginfo-46.3-5.el8_6.x86_64.rpm SHA-256: ea04b660684237f4341bb41b33b9df8d5c3c06d136a173949459953ab705600e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility