Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3298 - Security Advisory
Issued:
2026-02-25
Updated:
2026-02-25

RHSA-2026:3298 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: buildah security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for buildah is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
  • crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
  • BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url
  • BZ - 2437111 - CVE-2025-68121 crypto/tls: Unexpected session resumption in crypto/tls

CVEs

  • CVE-2025-61726
  • CVE-2025-61729
  • CVE-2025-68121

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
buildah-1.41.8-2.el9_7.src.rpm SHA-256: 679c557afa7a55961afe398fb4317a5b3611e158ffdcf84f2e6ac3b87e1f1832
x86_64
buildah-1.41.8-2.el9_7.x86_64.rpm SHA-256: f67abaf4c7689982592bee55ef493c42cc41ecde1ec46cb1b8b8598602b7a102
buildah-debuginfo-1.41.8-2.el9_7.x86_64.rpm SHA-256: c6f01c59ae84caaf6833777a990a63884cc008c3ec66f61cb210653b0e286102
buildah-debugsource-1.41.8-2.el9_7.x86_64.rpm SHA-256: d34625d86e4db4867f7982491cdccf0e2d6bf91c178030c5f209f8066d02b9ed
buildah-tests-1.41.8-2.el9_7.x86_64.rpm SHA-256: 1123d626234921c1334ae551b4a3e884c0a1ef9685647c7e209d70e92e15c700
buildah-tests-debuginfo-1.41.8-2.el9_7.x86_64.rpm SHA-256: 59fdc666cc8cec7ba9963d3c6718fb6fc12bd0cc969a709775cf8451d166f3c1

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
buildah-1.41.8-2.el9_7.src.rpm SHA-256: 679c557afa7a55961afe398fb4317a5b3611e158ffdcf84f2e6ac3b87e1f1832
s390x
buildah-1.41.8-2.el9_7.s390x.rpm SHA-256: 6635605c84dcae5ae5fd86f07a9662727017c0f30cac2a4b12181077ec040cff
buildah-debuginfo-1.41.8-2.el9_7.s390x.rpm SHA-256: 31032a596f72930920d79cfbc2ca5b9053401a04d020f266e70dbc3ba73289ff
buildah-debugsource-1.41.8-2.el9_7.s390x.rpm SHA-256: 22c69df35d9d316540220ccd1b261f26ede4c725d536c5cdbefc1568fe8b6dfa
buildah-tests-1.41.8-2.el9_7.s390x.rpm SHA-256: e9a2060df517119e782d542249a4bd4654d1f3eaebc7d6c9b7a4947bb58c433f
buildah-tests-debuginfo-1.41.8-2.el9_7.s390x.rpm SHA-256: 15a0e5c5b48a23616aabbac5b2a2d49d5b6a0017b2873946960fd616feb7dee3

Red Hat Enterprise Linux for Power, little endian 9

SRPM
buildah-1.41.8-2.el9_7.src.rpm SHA-256: 679c557afa7a55961afe398fb4317a5b3611e158ffdcf84f2e6ac3b87e1f1832
ppc64le
buildah-1.41.8-2.el9_7.ppc64le.rpm SHA-256: 9a817e2d0eef03b3c628521acb1d4be9f28e23ae94cac366d16924b6c34dd294
buildah-debuginfo-1.41.8-2.el9_7.ppc64le.rpm SHA-256: a224badee15270d44a8aeadcb6af5003a3d84ce84e79e44d3ce08b73c9af2413
buildah-debugsource-1.41.8-2.el9_7.ppc64le.rpm SHA-256: 3e7ccb15055c7cb6b7b853d2d690eba29e2107100528e1f0ee984af203fd8526
buildah-tests-1.41.8-2.el9_7.ppc64le.rpm SHA-256: 4815009896cb0b2c1fe071a6d4097959dbae103ec064b8dd0548784a84bb29bf
buildah-tests-debuginfo-1.41.8-2.el9_7.ppc64le.rpm SHA-256: df382f14bba29bb4d0224d15f02a6e3eb5267ccc8985d700fc9661cd22a1815c

Red Hat Enterprise Linux for ARM 64 9

SRPM
buildah-1.41.8-2.el9_7.src.rpm SHA-256: 679c557afa7a55961afe398fb4317a5b3611e158ffdcf84f2e6ac3b87e1f1832
aarch64
buildah-1.41.8-2.el9_7.aarch64.rpm SHA-256: 1edd212e308531f3acd0bdb7dac5557256d1128040ca57e1f1677df3bac10ce7
buildah-debuginfo-1.41.8-2.el9_7.aarch64.rpm SHA-256: fa8a676a6536e93688a96c057858544fef55295155dec9f0d88f84a786fbc2ad
buildah-debugsource-1.41.8-2.el9_7.aarch64.rpm SHA-256: 6020115e890aca72ca83f1918736ceb76ee5a0665f2511565fd788fe0506c22a
buildah-tests-1.41.8-2.el9_7.aarch64.rpm SHA-256: 9f7a6db446514259fce16240a037dd00b17f7ef556688e7e3e45bded1ab11958
buildah-tests-debuginfo-1.41.8-2.el9_7.aarch64.rpm SHA-256: ab24b8febb8d8ffa1ce1d9fba0451cd3598adfe5b5e8be920a1a0521fdedf5be

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility