Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3898 - Security Advisory
Issued:
2026-03-05
Updated:
2026-03-05

RHSA-2026:3898 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
  • crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x

Fixes

  • BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url
  • BZ - 2437111 - CVE-2025-68121 crypto/tls: Unexpected session resumption in crypto/tls

CVEs

  • CVE-2025-61726
  • CVE-2025-68121

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
osbuild-composer-101.4-4.el8_10.src.rpm SHA-256: 345aa579077f074a92625c7f9132178ce6abfa8de39df6b0188799e320c20d7e
x86_64
osbuild-composer-101.4-4.el8_10.x86_64.rpm SHA-256: c36cc952dc51b4aeb6e0143032bbf1cd3fca3dd1742b1a9beb0524916d2fe867
osbuild-composer-core-101.4-4.el8_10.x86_64.rpm SHA-256: e2a2a1ed941143e864553fc7f6c92c212f3b4cef9b3ace96b401d33e27c0545b
osbuild-composer-core-debuginfo-101.4-4.el8_10.x86_64.rpm SHA-256: 7842ae7bdbd5dfd16fbe85a6fefcda5e174895e88912c8d5cac74a78fb9a1249
osbuild-composer-debuginfo-101.4-4.el8_10.x86_64.rpm SHA-256: 8846d294a9f40dcaab775d1be569d990438ce611e3f81be8dae9feea6c470124
osbuild-composer-debugsource-101.4-4.el8_10.x86_64.rpm SHA-256: 6b5bd860b5a115645e65260fe6f1d1a695e52b04b734878b8a56aa5b641e39fe
osbuild-composer-tests-debuginfo-101.4-4.el8_10.x86_64.rpm SHA-256: fb9fc9dbf8f0852cff0569c0e49657c3c070a2cb11ebbf46f3499141829ccc9f
osbuild-composer-worker-101.4-4.el8_10.x86_64.rpm SHA-256: a93de1a6f7b93836e5fafc10f8dca5c8f3d163dea884f14fab207fad513f2215
osbuild-composer-worker-debuginfo-101.4-4.el8_10.x86_64.rpm SHA-256: d7931e0c938f14e51d356abf60d763c0f158592448bfc76d6105356f46c4c6ff

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
osbuild-composer-101.4-4.el8_10.src.rpm SHA-256: 345aa579077f074a92625c7f9132178ce6abfa8de39df6b0188799e320c20d7e
s390x
osbuild-composer-101.4-4.el8_10.s390x.rpm SHA-256: e4a7e49dc925f4c47a36360aa5f5fdc0343fb67580c2a8520f58a77b5a07e8c2
osbuild-composer-core-101.4-4.el8_10.s390x.rpm SHA-256: b9c07bfc8fdb280a313deeaa8ec2a76e21842b731e2458c0c7201f31ad90bd78
osbuild-composer-core-debuginfo-101.4-4.el8_10.s390x.rpm SHA-256: 744d5210c1773d57e6b0dad32f25d035f39c811b6440be1986e4ced38d943062
osbuild-composer-debuginfo-101.4-4.el8_10.s390x.rpm SHA-256: 97b80f54ef4f5c44e9342a799465061a1e1f0f1d35a71587a765bd638ffeabd6
osbuild-composer-debugsource-101.4-4.el8_10.s390x.rpm SHA-256: fdf155afc4dc0c48a45ecd24153a2355e83f0e660dcbf97486a1a4b725eb430a
osbuild-composer-tests-debuginfo-101.4-4.el8_10.s390x.rpm SHA-256: 35f6333e8451b163d2566cb148e95aad407ae4407520fbc45a706445e937dc01
osbuild-composer-worker-101.4-4.el8_10.s390x.rpm SHA-256: c3ba6b9e0ddce3aaaa24787d60f2b39b5db218b96266c2a42ee79784a1634098
osbuild-composer-worker-debuginfo-101.4-4.el8_10.s390x.rpm SHA-256: 980b250e0b9bcd26a1c1b8f425aaaca4dfd0765ddd73fe27718f138d8362ba6d

Red Hat Enterprise Linux for Power, little endian 8

SRPM
osbuild-composer-101.4-4.el8_10.src.rpm SHA-256: 345aa579077f074a92625c7f9132178ce6abfa8de39df6b0188799e320c20d7e
ppc64le
osbuild-composer-101.4-4.el8_10.ppc64le.rpm SHA-256: 1de873c9ef9ec8cac94b1a33c4f997fca06409e881d27dc7efa6668420b1df79
osbuild-composer-core-101.4-4.el8_10.ppc64le.rpm SHA-256: e2efc955ee5c80a932fd12b8c67ab6692f57a63891ac4b0fc82a7c49c31260f3
osbuild-composer-core-debuginfo-101.4-4.el8_10.ppc64le.rpm SHA-256: 0bed1f51d3b64286a34707e0bfcd59c6234e837d8dc71cb5550d8cb82805ec5c
osbuild-composer-debuginfo-101.4-4.el8_10.ppc64le.rpm SHA-256: bf7dd698053dad8ffc9e2ac1a23cd9f9ff5183a759f738132eb6b518b62ada79
osbuild-composer-debugsource-101.4-4.el8_10.ppc64le.rpm SHA-256: 6f63d2a654834db1dca0105337dea4803793ff4688b9971a6ae37e4d7a46bc5f
osbuild-composer-tests-debuginfo-101.4-4.el8_10.ppc64le.rpm SHA-256: fd8d6dff11f6d0b0a6d3dd2cec4e79db8286902cafdeabe8507868ce2ea3188a
osbuild-composer-worker-101.4-4.el8_10.ppc64le.rpm SHA-256: 0d6a8fb9f176d946446b754580ce6413b99603fee34cd05d6e0ef14773c9250c
osbuild-composer-worker-debuginfo-101.4-4.el8_10.ppc64le.rpm SHA-256: 2ca201a051e6f524a4fd4b9652bc942e9b69486b3a2d15496974e384edb7f6e7

Red Hat Enterprise Linux for ARM 64 8

SRPM
osbuild-composer-101.4-4.el8_10.src.rpm SHA-256: 345aa579077f074a92625c7f9132178ce6abfa8de39df6b0188799e320c20d7e
aarch64
osbuild-composer-101.4-4.el8_10.aarch64.rpm SHA-256: b02bf0fdd1ce59a3c181243288dd9cf69abf03b0e840a361e4b0a6902fd7666a
osbuild-composer-core-101.4-4.el8_10.aarch64.rpm SHA-256: c2b509ee2bb1141273d25191b1542f461b69400815e06cf67151c957d54a7ed7
osbuild-composer-core-debuginfo-101.4-4.el8_10.aarch64.rpm SHA-256: 268e2ca7e8c3cb88bf0a517c6898c7e41eacf907f061cd4161119f553cc258e8
osbuild-composer-debuginfo-101.4-4.el8_10.aarch64.rpm SHA-256: 62542628876a86b3eb6533f287a24bc075c1e2cf22053d488f0ff70bf89e4914
osbuild-composer-debugsource-101.4-4.el8_10.aarch64.rpm SHA-256: c23689f899f13699bebdcfdbfe9279b8f98c6a7a1b88f1015be6273a6a937ff0
osbuild-composer-tests-debuginfo-101.4-4.el8_10.aarch64.rpm SHA-256: cfe831690ab332f0d418ee87bf0b47ef22ebdb52ecebf591f9568eb3e3d3eb86
osbuild-composer-worker-101.4-4.el8_10.aarch64.rpm SHA-256: 589ebc46df3f5a86884a2f74fbd3df771329e04b32c104ee73a7445e4bf25330
osbuild-composer-worker-debuginfo-101.4-4.el8_10.aarch64.rpm SHA-256: 24a1a9cd95db158f69e9b7697319524d688ccf80c0687842e833d2ff6bc1f4ac

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.4-4.el8_10.src.rpm SHA-256: 345aa579077f074a92625c7f9132178ce6abfa8de39df6b0188799e320c20d7e
x86_64
osbuild-composer-101.4-4.el8_10.x86_64.rpm SHA-256: c36cc952dc51b4aeb6e0143032bbf1cd3fca3dd1742b1a9beb0524916d2fe867
osbuild-composer-core-101.4-4.el8_10.x86_64.rpm SHA-256: e2a2a1ed941143e864553fc7f6c92c212f3b4cef9b3ace96b401d33e27c0545b
osbuild-composer-core-debuginfo-101.4-4.el8_10.x86_64.rpm SHA-256: 7842ae7bdbd5dfd16fbe85a6fefcda5e174895e88912c8d5cac74a78fb9a1249
osbuild-composer-debuginfo-101.4-4.el8_10.x86_64.rpm SHA-256: 8846d294a9f40dcaab775d1be569d990438ce611e3f81be8dae9feea6c470124
osbuild-composer-debugsource-101.4-4.el8_10.x86_64.rpm SHA-256: 6b5bd860b5a115645e65260fe6f1d1a695e52b04b734878b8a56aa5b641e39fe
osbuild-composer-tests-debuginfo-101.4-4.el8_10.x86_64.rpm SHA-256: fb9fc9dbf8f0852cff0569c0e49657c3c070a2cb11ebbf46f3499141829ccc9f
osbuild-composer-worker-101.4-4.el8_10.x86_64.rpm SHA-256: a93de1a6f7b93836e5fafc10f8dca5c8f3d163dea884f14fab207fad513f2215
osbuild-composer-worker-debuginfo-101.4-4.el8_10.x86_64.rpm SHA-256: d7931e0c938f14e51d356abf60d763c0f158592448bfc76d6105356f46c4c6ff

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.4-4.el8_10.src.rpm SHA-256: 345aa579077f074a92625c7f9132178ce6abfa8de39df6b0188799e320c20d7e
aarch64
osbuild-composer-101.4-4.el8_10.aarch64.rpm SHA-256: b02bf0fdd1ce59a3c181243288dd9cf69abf03b0e840a361e4b0a6902fd7666a
osbuild-composer-core-101.4-4.el8_10.aarch64.rpm SHA-256: c2b509ee2bb1141273d25191b1542f461b69400815e06cf67151c957d54a7ed7
osbuild-composer-core-debuginfo-101.4-4.el8_10.aarch64.rpm SHA-256: 268e2ca7e8c3cb88bf0a517c6898c7e41eacf907f061cd4161119f553cc258e8
osbuild-composer-debuginfo-101.4-4.el8_10.aarch64.rpm SHA-256: 62542628876a86b3eb6533f287a24bc075c1e2cf22053d488f0ff70bf89e4914
osbuild-composer-debugsource-101.4-4.el8_10.aarch64.rpm SHA-256: c23689f899f13699bebdcfdbfe9279b8f98c6a7a1b88f1015be6273a6a937ff0
osbuild-composer-tests-debuginfo-101.4-4.el8_10.aarch64.rpm SHA-256: cfe831690ab332f0d418ee87bf0b47ef22ebdb52ecebf591f9568eb3e3d3eb86
osbuild-composer-worker-101.4-4.el8_10.aarch64.rpm SHA-256: 589ebc46df3f5a86884a2f74fbd3df771329e04b32c104ee73a7445e4bf25330
osbuild-composer-worker-debuginfo-101.4-4.el8_10.aarch64.rpm SHA-256: 24a1a9cd95db158f69e9b7697319524d688ccf80c0687842e833d2ff6bc1f4ac

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.4-4.el8_10.src.rpm SHA-256: 345aa579077f074a92625c7f9132178ce6abfa8de39df6b0188799e320c20d7e
ppc64le
osbuild-composer-101.4-4.el8_10.ppc64le.rpm SHA-256: 1de873c9ef9ec8cac94b1a33c4f997fca06409e881d27dc7efa6668420b1df79
osbuild-composer-core-101.4-4.el8_10.ppc64le.rpm SHA-256: e2efc955ee5c80a932fd12b8c67ab6692f57a63891ac4b0fc82a7c49c31260f3
osbuild-composer-core-debuginfo-101.4-4.el8_10.ppc64le.rpm SHA-256: 0bed1f51d3b64286a34707e0bfcd59c6234e837d8dc71cb5550d8cb82805ec5c
osbuild-composer-debuginfo-101.4-4.el8_10.ppc64le.rpm SHA-256: bf7dd698053dad8ffc9e2ac1a23cd9f9ff5183a759f738132eb6b518b62ada79
osbuild-composer-debugsource-101.4-4.el8_10.ppc64le.rpm SHA-256: 6f63d2a654834db1dca0105337dea4803793ff4688b9971a6ae37e4d7a46bc5f
osbuild-composer-tests-debuginfo-101.4-4.el8_10.ppc64le.rpm SHA-256: fd8d6dff11f6d0b0a6d3dd2cec4e79db8286902cafdeabe8507868ce2ea3188a
osbuild-composer-worker-101.4-4.el8_10.ppc64le.rpm SHA-256: 0d6a8fb9f176d946446b754580ce6413b99603fee34cd05d6e0ef14773c9250c
osbuild-composer-worker-debuginfo-101.4-4.el8_10.ppc64le.rpm SHA-256: 2ca201a051e6f524a4fd4b9652bc942e9b69486b3a2d15496974e384edb7f6e7

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.4-4.el8_10.src.rpm SHA-256: 345aa579077f074a92625c7f9132178ce6abfa8de39df6b0188799e320c20d7e
s390x
osbuild-composer-101.4-4.el8_10.s390x.rpm SHA-256: e4a7e49dc925f4c47a36360aa5f5fdc0343fb67580c2a8520f58a77b5a07e8c2
osbuild-composer-core-101.4-4.el8_10.s390x.rpm SHA-256: b9c07bfc8fdb280a313deeaa8ec2a76e21842b731e2458c0c7201f31ad90bd78
osbuild-composer-core-debuginfo-101.4-4.el8_10.s390x.rpm SHA-256: 744d5210c1773d57e6b0dad32f25d035f39c811b6440be1986e4ced38d943062
osbuild-composer-debuginfo-101.4-4.el8_10.s390x.rpm SHA-256: 97b80f54ef4f5c44e9342a799465061a1e1f0f1d35a71587a765bd638ffeabd6
osbuild-composer-debugsource-101.4-4.el8_10.s390x.rpm SHA-256: fdf155afc4dc0c48a45ecd24153a2355e83f0e660dcbf97486a1a4b725eb430a
osbuild-composer-tests-debuginfo-101.4-4.el8_10.s390x.rpm SHA-256: 35f6333e8451b163d2566cb148e95aad407ae4407520fbc45a706445e937dc01
osbuild-composer-worker-101.4-4.el8_10.s390x.rpm SHA-256: c3ba6b9e0ddce3aaaa24787d60f2b39b5db218b96266c2a42ee79784a1634098
osbuild-composer-worker-debuginfo-101.4-4.el8_10.s390x.rpm SHA-256: 980b250e0b9bcd26a1c1b8f425aaaca4dfd0765ddd73fe27718f138d8362ba6d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility