Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3752 - Security Advisory
Issued:
2026-03-04
Updated:
2026-03-04

RHSA-2026:3752 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  • golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)
  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
  • crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
  • BZ - 2434431 - CVE-2025-61728 golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip
  • BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url
  • BZ - 2437111 - CVE-2025-68121 crypto/tls: Unexpected session resumption in crypto/tls

CVEs

  • CVE-2025-61726
  • CVE-2025-61728
  • CVE-2025-61729
  • CVE-2025-68121

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
osbuild-composer-149-5.el10_1.src.rpm SHA-256: e03e2c7bd4c7ffdfec1e70fdc931ac3aeac8c16f1a6cb97fd272bb259afe396d
x86_64
osbuild-composer-149-5.el10_1.x86_64.rpm SHA-256: 1c7c6003dbcb0419d329650f54b3507351ba5e578685396e492ebd8e59a82e9c
osbuild-composer-core-149-5.el10_1.x86_64.rpm SHA-256: 4e5b446e16361442c883edf2f94fe41b2693dc0a681b36c913d71da100e54cc8
osbuild-composer-core-debuginfo-149-5.el10_1.x86_64.rpm SHA-256: dc5e982911f7f7c0b57bcea842b35880bfe97e95087e19973cc951196edb18b8
osbuild-composer-debugsource-149-5.el10_1.x86_64.rpm SHA-256: 35625ec9b0d40c3bc39338053abc2b738aaea01a051ad7c589c8b365aa9e545f
osbuild-composer-tests-debuginfo-149-5.el10_1.x86_64.rpm SHA-256: cf548f65dfd3f3a63f4a5f11ed8aabb010a249b4e10840feb9562d6ba447b4a0
osbuild-composer-worker-149-5.el10_1.x86_64.rpm SHA-256: a8b2a9e4016f9ce7c25a34aa38f27a3f96f67b11d8ff81cef9a8a8ebbe3dd750
osbuild-composer-worker-debuginfo-149-5.el10_1.x86_64.rpm SHA-256: 54f7ecfb845cfb7459d20af00e22ba4f4550a9b0f1db03c9abc2096c2b89dd2c

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
osbuild-composer-149-5.el10_1.src.rpm SHA-256: e03e2c7bd4c7ffdfec1e70fdc931ac3aeac8c16f1a6cb97fd272bb259afe396d
s390x
osbuild-composer-149-5.el10_1.s390x.rpm SHA-256: 9d0990a7ce28d57192142809a1eeb2a0c0158346d87243d2ebcfa3abf89b18ea
osbuild-composer-core-149-5.el10_1.s390x.rpm SHA-256: fce557a938d14b1fd9cfc550d1bdba5e29d597eaee31a525830427ec21dc3ea1
osbuild-composer-core-debuginfo-149-5.el10_1.s390x.rpm SHA-256: 3f71d60420c8118df76a50f88d341454fad11366906dfeb13248f722edbc63ee
osbuild-composer-debugsource-149-5.el10_1.s390x.rpm SHA-256: f0357d00889a87f65fd2d9b9cd92d35e44683513d10caa5722054da949762e89
osbuild-composer-tests-debuginfo-149-5.el10_1.s390x.rpm SHA-256: 844b7c051d7dd597879dbe965664c7339e16e86071a65d94727a8764bf4551df
osbuild-composer-worker-149-5.el10_1.s390x.rpm SHA-256: b8a3a5100d7fd37f406b180be64641e6de572a2670dd82eaf0d4721101a1356e
osbuild-composer-worker-debuginfo-149-5.el10_1.s390x.rpm SHA-256: fe690340abe7b3bf66a823342be9ad8cc41dc0a1fd1f5406dc2776a29226d4db

Red Hat Enterprise Linux for Power, little endian 10

SRPM
osbuild-composer-149-5.el10_1.src.rpm SHA-256: e03e2c7bd4c7ffdfec1e70fdc931ac3aeac8c16f1a6cb97fd272bb259afe396d
ppc64le
osbuild-composer-149-5.el10_1.ppc64le.rpm SHA-256: bd450b6b0be8e0d9d968d4911814c2eb7ad468b69256a23caadb66d563ab21e5
osbuild-composer-core-149-5.el10_1.ppc64le.rpm SHA-256: 51e20b0982b8fa8549a3965c6c00501c227eb9019fd8c0ee107e59aa2aeacbb4
osbuild-composer-core-debuginfo-149-5.el10_1.ppc64le.rpm SHA-256: 0f6acbb031f86268a8b4e50ed43f435cfb5af5fcd73012f8f27a3ee26acb6f2a
osbuild-composer-debugsource-149-5.el10_1.ppc64le.rpm SHA-256: cba631d5c155d94ad7ce31305d875910bc998de20649991cc657046265c80456
osbuild-composer-tests-debuginfo-149-5.el10_1.ppc64le.rpm SHA-256: b7565e047c7656428f937167845db087a2c418a51ecc3c30a6efbc8dca6fefb1
osbuild-composer-worker-149-5.el10_1.ppc64le.rpm SHA-256: 4e00897c498957073d1e4e55d7815b8a17522f0bc1bb7ccd17302b23a9c7bc34
osbuild-composer-worker-debuginfo-149-5.el10_1.ppc64le.rpm SHA-256: 9e6b919210d9ed45488fcc2a3f7c08afffbda1b41733b0d8ccd5ce4661cefea1

Red Hat Enterprise Linux for ARM 64 10

SRPM
osbuild-composer-149-5.el10_1.src.rpm SHA-256: e03e2c7bd4c7ffdfec1e70fdc931ac3aeac8c16f1a6cb97fd272bb259afe396d
aarch64
osbuild-composer-149-5.el10_1.aarch64.rpm SHA-256: 2c3c05cd9dafea46a660a52389c3887a8bfd3cde1630f0631af5587ceffd8118
osbuild-composer-core-149-5.el10_1.aarch64.rpm SHA-256: 810c914f82d0b53a754e7424dd517dfe17789281a44db15fbf0152524f345fc9
osbuild-composer-core-debuginfo-149-5.el10_1.aarch64.rpm SHA-256: f0e8c0af8e1814bbbba6962d3836dea155a5972976537153778d2cc4217d9252
osbuild-composer-debugsource-149-5.el10_1.aarch64.rpm SHA-256: b4c93487c9cd65190c2486bcb56e0f1f81152f43d8d64fb08a5f6ace19632982
osbuild-composer-tests-debuginfo-149-5.el10_1.aarch64.rpm SHA-256: ff66bf4b50eca8fe06ce1de9bcf326fd88db237db0db9f172f6477f67b06c8b4
osbuild-composer-worker-149-5.el10_1.aarch64.rpm SHA-256: 79117d6a85a30aa6bb1594b1394e1e11fafdb1bbf922371be01a597edc1e068b
osbuild-composer-worker-debuginfo-149-5.el10_1.aarch64.rpm SHA-256: d0244faedc038a12a1e2299623aa3a60816353dd1588989474574dce176e0d97

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility