Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:4532 - Security Advisory
Issued:
2026-03-12
Updated:
2026-03-12

RHSA-2026:4532 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: buildah security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for buildah is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)
  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)
  • golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)
  • github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload (CVE-2025-65637)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2404715 - CVE-2025-52881 runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects
  • BZ - 2407258 - CVE-2025-58183 golang: archive/tar: Unbounded allocation when parsing GNU sparse map
  • BZ - 2414943 - CVE-2025-47913 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS
  • BZ - 2418900 - CVE-2025-65637 github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload

CVEs

  • CVE-2025-47913
  • CVE-2025-52881
  • CVE-2025-58183
  • CVE-2025-65637

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
buildah-1.29.5-1.el9_2.2.src.rpm SHA-256: cef754f2754540f2936f110e42804e7c0b570ea06ebcacc81a7fbbf5af127697
x86_64
buildah-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: 20c40c44f514f2f4c171e9753b8f1d2edf3818b1a30a46046acc7953d18bac7e
buildah-debuginfo-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: feaee199e04890aca8b076ec8d7827d72e828873cd1fbc2bae75bb54d70124ca
buildah-debugsource-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: 9c7f20b733740c9b6d6939ca22e1fa414eefcbbf3cdb19927c60b95c998afe27
buildah-tests-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: 5d7ca7e7b5e13695f47815cd9879105aa856e633bbe0fc4fec1b970344ca231f
buildah-tests-debuginfo-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: f3d891f66cedf0dfe97f3ae0eed0146ab9c1e338a82cd8b798218b5126b34f42

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
buildah-1.29.5-1.el9_2.2.src.rpm SHA-256: cef754f2754540f2936f110e42804e7c0b570ea06ebcacc81a7fbbf5af127697
ppc64le
buildah-1.29.5-1.el9_2.2.ppc64le.rpm SHA-256: be4d516dd9240204425dacd6fba5a3e1476bf1af16c9180425879759147d6648
buildah-debuginfo-1.29.5-1.el9_2.2.ppc64le.rpm SHA-256: 818f5806ff5119dcc37eb8ba0af0109486e18e7dd7071a1c3d21088dd38cdcab
buildah-debugsource-1.29.5-1.el9_2.2.ppc64le.rpm SHA-256: d6a16ef0190eedb8c6b549da24a193491fb2bb1d1866e3db98de37e47859a6d6
buildah-tests-1.29.5-1.el9_2.2.ppc64le.rpm SHA-256: 4331e9e01b2d0c94bb9124f7ad3758526aa3c2fb4fe004cd3d0701fc308f8e08
buildah-tests-debuginfo-1.29.5-1.el9_2.2.ppc64le.rpm SHA-256: 8811a9384639f78e720be25955316ff97da6698fe6990c383c7ac356f5a4b082

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
buildah-1.29.5-1.el9_2.2.src.rpm SHA-256: cef754f2754540f2936f110e42804e7c0b570ea06ebcacc81a7fbbf5af127697
x86_64
buildah-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: 20c40c44f514f2f4c171e9753b8f1d2edf3818b1a30a46046acc7953d18bac7e
buildah-debuginfo-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: feaee199e04890aca8b076ec8d7827d72e828873cd1fbc2bae75bb54d70124ca
buildah-debugsource-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: 9c7f20b733740c9b6d6939ca22e1fa414eefcbbf3cdb19927c60b95c998afe27
buildah-tests-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: 5d7ca7e7b5e13695f47815cd9879105aa856e633bbe0fc4fec1b970344ca231f
buildah-tests-debuginfo-1.29.5-1.el9_2.2.x86_64.rpm SHA-256: f3d891f66cedf0dfe97f3ae0eed0146ab9c1e338a82cd8b798218b5126b34f42

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
buildah-1.29.5-1.el9_2.2.src.rpm SHA-256: cef754f2754540f2936f110e42804e7c0b570ea06ebcacc81a7fbbf5af127697
aarch64
buildah-1.29.5-1.el9_2.2.aarch64.rpm SHA-256: 90bf6f9b9206202c9f7e12c354a717c2c2f138d075bbf647cda6bb0e64dbdf27
buildah-debuginfo-1.29.5-1.el9_2.2.aarch64.rpm SHA-256: 513417f20b6116498f930f06e660a7a8966521ac7c0516cfad56a4786ff99579
buildah-debugsource-1.29.5-1.el9_2.2.aarch64.rpm SHA-256: f1202f24b8b7e99b5b11db8e2768518965eda9bd580d0556660f1be792a1fecf
buildah-tests-1.29.5-1.el9_2.2.aarch64.rpm SHA-256: edbfc8f99533b3e4c3bbfd83bddf3ccf3643a340d3ad242c97bb7a545cce0ece
buildah-tests-debuginfo-1.29.5-1.el9_2.2.aarch64.rpm SHA-256: 4e8bbec5a21ce029c8f731fc709a087978cc1d855408835c598274a40fb1995f

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
buildah-1.29.5-1.el9_2.2.src.rpm SHA-256: cef754f2754540f2936f110e42804e7c0b570ea06ebcacc81a7fbbf5af127697
s390x
buildah-1.29.5-1.el9_2.2.s390x.rpm SHA-256: d84aee8fda1da1e43786e0a87bfe6c28ef2361049724a3a2867ca15c0ebdf481
buildah-debuginfo-1.29.5-1.el9_2.2.s390x.rpm SHA-256: bb4ae46d03e4617f1894cd14dc0d74484b8f5f8bb54742ae1a066e913749e03d
buildah-debugsource-1.29.5-1.el9_2.2.s390x.rpm SHA-256: b37cc2aca944ccb80f2aa73b965c12af10e11e4bf73b0399fd3b0730bbce9da1
buildah-tests-1.29.5-1.el9_2.2.s390x.rpm SHA-256: 616b0300fe5212633c6dd2845c75891f7610dd387f6b1d9aba528fd45590b6ec
buildah-tests-debuginfo-1.29.5-1.el9_2.2.s390x.rpm SHA-256: 223e180b5189ec0d75fdc34d004641f3ad1188f7bbe4659cc062699b68d3f551

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility