Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3753 - Security Advisory
Issued:
2026-03-04
Updated:
2026-03-04

RHSA-2026:3753 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  • golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)
  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
  • crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
  • BZ - 2434431 - CVE-2025-61728 golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip
  • BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url
  • BZ - 2437111 - CVE-2025-68121 crypto/tls: Unexpected session resumption in crypto/tls

CVEs

  • CVE-2025-61726
  • CVE-2025-61728
  • CVE-2025-61729
  • CVE-2025-68121

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
osbuild-composer-149-4.el9_7.src.rpm SHA-256: 541ad139dc80b24c36d6e8abf867cf36308fb64d157e917b66d0418c1c75b6d5
x86_64
osbuild-composer-149-4.el9_7.x86_64.rpm SHA-256: 5fbcd8efb5b1c732372d64f7fd7bc85d6cfc08845c2548111f511aa082d3069b
osbuild-composer-core-149-4.el9_7.x86_64.rpm SHA-256: 779b5762eb3c241354a6979c9d6b277682c146c58253f889c510b9e999970931
osbuild-composer-core-debuginfo-149-4.el9_7.x86_64.rpm SHA-256: c92e528896aa31af21fe199f1cc4c224a5cc38e6bdb4dc80b500ca706887b83f
osbuild-composer-debuginfo-149-4.el9_7.x86_64.rpm SHA-256: f647e3f75fd2fad02d11b1895ffb418ac50b86d3f59c2ed92431dc1e0c9771f5
osbuild-composer-debugsource-149-4.el9_7.x86_64.rpm SHA-256: 3f9bd6b4d196fe350534ced9ca6d066f64e5536d5d447c30bd28d85d03f8e67c
osbuild-composer-tests-debuginfo-149-4.el9_7.x86_64.rpm SHA-256: 5b3194a1daed98a6a3ec32176787ddbe85d8e933db9be535d13a72a76c04c7c0
osbuild-composer-worker-149-4.el9_7.x86_64.rpm SHA-256: 88927bcd09c1d5201e66cfe0196ef849ac3c9fa8c5894bffc4b8b6296a13a09d
osbuild-composer-worker-debuginfo-149-4.el9_7.x86_64.rpm SHA-256: 16b4b34096dc2e0004b30dc5807064e80fd8f386bf3af2b4738050692f8071cc

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
osbuild-composer-149-4.el9_7.src.rpm SHA-256: 541ad139dc80b24c36d6e8abf867cf36308fb64d157e917b66d0418c1c75b6d5
s390x
osbuild-composer-149-4.el9_7.s390x.rpm SHA-256: 265e06c1e7a4f2e2948547c3a4c037a9679b1771640f23b9c319feb898c5f558
osbuild-composer-core-149-4.el9_7.s390x.rpm SHA-256: 778c5bb427303ee1104238e1ee4f8eed0d2fab90c9553bbfea30119d0393f2ee
osbuild-composer-core-debuginfo-149-4.el9_7.s390x.rpm SHA-256: 385c29e2daf8c9ebb0d57c1b613eda6f75d1383896bea045cf02c3f4e94b2371
osbuild-composer-debuginfo-149-4.el9_7.s390x.rpm SHA-256: 036d67cc09f682684a7253560d9e3e6c833133deb0b0db2b1cccecca4f3ebacf
osbuild-composer-debugsource-149-4.el9_7.s390x.rpm SHA-256: 1daa0af8de37d07841fe451d6e76ff741b7f0de693f828e6b1c00cc531334500
osbuild-composer-tests-debuginfo-149-4.el9_7.s390x.rpm SHA-256: 1c71c4185b85722f915c4c77deae4c4b67d68cc166c5ac7a3ad913beeddd2cc6
osbuild-composer-worker-149-4.el9_7.s390x.rpm SHA-256: 73480df630bf2ceed2276d95e1141e4aa726302885f10d31d0a14cde84f950c6
osbuild-composer-worker-debuginfo-149-4.el9_7.s390x.rpm SHA-256: 275dd7c8964ae847df75d6455b3241dcf2bc6d1833eb1fc49d9d9a1370aea8f1

Red Hat Enterprise Linux for Power, little endian 9

SRPM
osbuild-composer-149-4.el9_7.src.rpm SHA-256: 541ad139dc80b24c36d6e8abf867cf36308fb64d157e917b66d0418c1c75b6d5
ppc64le
osbuild-composer-149-4.el9_7.ppc64le.rpm SHA-256: 3dbfacdb741acd8436ce1873451cb8a0e9f605f043892dac3095a80f8e11d575
osbuild-composer-core-149-4.el9_7.ppc64le.rpm SHA-256: 63bc0336a6cc0fe27fdf652b4cc051d8f6535ffdabc7ed35e72de13323b9296b
osbuild-composer-core-debuginfo-149-4.el9_7.ppc64le.rpm SHA-256: 01523df82f568fb4ebeda2ebb3945651970c16ea844de946c4dc62c358ee0c20
osbuild-composer-debuginfo-149-4.el9_7.ppc64le.rpm SHA-256: b156e4074b43f2dd827577ee18dd125ee45cc832c6efbcd0335c04db7aa2f0ee
osbuild-composer-debugsource-149-4.el9_7.ppc64le.rpm SHA-256: 70196f3673caa6b5eb78a525e4770da2d6338d4fc1d89adaf996c6c8b289cbcd
osbuild-composer-tests-debuginfo-149-4.el9_7.ppc64le.rpm SHA-256: 915fa2c2ab2e8d253d604468dfbb6db70c33e5af731e665f67a4f443b5776304
osbuild-composer-worker-149-4.el9_7.ppc64le.rpm SHA-256: e7061bebe3290351aa0d1d6355fdc85ae86bfb6a5a5c2745dd1dc07b1efbeb86
osbuild-composer-worker-debuginfo-149-4.el9_7.ppc64le.rpm SHA-256: 6d48a48c5a3cf835078af7036a05a3ce3f96bf8d9eb219fff1a37019822f78fd

Red Hat Enterprise Linux for ARM 64 9

SRPM
osbuild-composer-149-4.el9_7.src.rpm SHA-256: 541ad139dc80b24c36d6e8abf867cf36308fb64d157e917b66d0418c1c75b6d5
aarch64
osbuild-composer-149-4.el9_7.aarch64.rpm SHA-256: 741d8e327656fca870ccc410fe7a641cc2ae4e98e35c52dcf16fe45cdd734f66
osbuild-composer-core-149-4.el9_7.aarch64.rpm SHA-256: 4d6ae6134e73cf9d00eba805c06d6dc676a80e2fc4044fa41326a554ca78b25d
osbuild-composer-core-debuginfo-149-4.el9_7.aarch64.rpm SHA-256: 1533b6779e60f0a68b78abe1c83f87fed43d2b60d4514e21c008a7ee63c23f64
osbuild-composer-debuginfo-149-4.el9_7.aarch64.rpm SHA-256: 3fcc3c5bfeb4185c05be8b6456fb3665ddaf6711e1c06ee2c681e4c3d78f864c
osbuild-composer-debugsource-149-4.el9_7.aarch64.rpm SHA-256: c2c4457552b486c58ce802c49f408112d7b5b5b10f6b449eecbc99a3aa89a111
osbuild-composer-tests-debuginfo-149-4.el9_7.aarch64.rpm SHA-256: 56303427ec69c4d9c482fbf576b3ee43f234400cb1b58669ab0bbfed0644837e
osbuild-composer-worker-149-4.el9_7.aarch64.rpm SHA-256: 5b3aa1ae1e255def45867492754120f246effd264a7bb8d6324f3fea0b019027
osbuild-composer-worker-debuginfo-149-4.el9_7.aarch64.rpm SHA-256: 85508b573173b9f8723f12379076f3701364ff0c8d407e5139f33e72ff1eedd7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility