Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:48790 - Security Advisory
Issued:
2026-07-30
Updated:
2026-07-30

RHSA-2026:48790 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)
  • github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
  • golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
  • crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
  • crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x

Fixes

  • BZ - 2449833 - CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
  • BZ - 2455470 - CVE-2026-34986 github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
  • BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
  • BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
  • BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building

CVEs

  • CVE-2026-32280
  • CVE-2026-32282
  • CVE-2026-32283
  • CVE-2026-33186
  • CVE-2026-34986

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
osbuild-composer-101.5-1.el8_10.src.rpm SHA-256: 59ecb77d910ce498a80fcbdf17db7556100f4a4afef49452f17867f852291031
x86_64
osbuild-composer-101.5-1.el8_10.x86_64.rpm SHA-256: 379afac5f696d619ef2b27573b63c528fadbbc1233928ef612e6dc960b4c7074
osbuild-composer-core-101.5-1.el8_10.x86_64.rpm SHA-256: be2ac777fb8c8062570a68ef80223c660be03b8c7fb9cf354a093a89a3752046
osbuild-composer-core-debuginfo-101.5-1.el8_10.x86_64.rpm SHA-256: 291e39c288c566c27562698662bee30c8668bc1e29c64eeb8253f75debf933f9
osbuild-composer-debuginfo-101.5-1.el8_10.x86_64.rpm SHA-256: bc42fe3eb2e6aabd30e0335f0828076556358e98971df6f071b53db2793b76cc
osbuild-composer-debugsource-101.5-1.el8_10.x86_64.rpm SHA-256: 3ade79319c32b1f954feb1927d1f10d238a4352e8befa26cb957f56c57275704
osbuild-composer-tests-debuginfo-101.5-1.el8_10.x86_64.rpm SHA-256: 6a0dbceeb9e7f9fd659a61f44264d0b4832540da570766c697a6d706b6ffddd7
osbuild-composer-worker-101.5-1.el8_10.x86_64.rpm SHA-256: f130a00386f47db5dea952c1cb8e4e05bde812809682975f7cdb1774c4fd50ff
osbuild-composer-worker-debuginfo-101.5-1.el8_10.x86_64.rpm SHA-256: d9b6ef49cee1ee576c392052fb8bf1f564d7e4e4e0156d5fd6497ac4b3bfe028

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
osbuild-composer-101.5-1.el8_10.src.rpm SHA-256: 59ecb77d910ce498a80fcbdf17db7556100f4a4afef49452f17867f852291031
s390x
osbuild-composer-101.5-1.el8_10.s390x.rpm SHA-256: 38df6b5646a98200f9e169a1b88ccf32823a4ae95e906b90f8528cccf91a71bc
osbuild-composer-core-101.5-1.el8_10.s390x.rpm SHA-256: 41b5fdb397f23fed94cee3aa90bad930d14fbe55a3e9fcf4cfeb7eccaa3c3bfb
osbuild-composer-core-debuginfo-101.5-1.el8_10.s390x.rpm SHA-256: 9ebcd61cfcc9e0c7df2c490f76d78f71243b515278f94fb6041099334c07c67a
osbuild-composer-debuginfo-101.5-1.el8_10.s390x.rpm SHA-256: a28bdbc0abd7c01fc9303f598c8be382132e5d9e785d096a422f01de0e7fc908
osbuild-composer-debugsource-101.5-1.el8_10.s390x.rpm SHA-256: fd3e5b32fd1b73feb72ce1f2c817f5792b18e95daeb95339c29f3082fc65e204
osbuild-composer-tests-debuginfo-101.5-1.el8_10.s390x.rpm SHA-256: 4257f6d71e61ed57173e03794e39e078f429c93abfd3fd50beca61d2e0980fc0
osbuild-composer-worker-101.5-1.el8_10.s390x.rpm SHA-256: 44fa30678f48c6ae406ee87ba695d2c46b9217268df59b392a778b7b79b71eed
osbuild-composer-worker-debuginfo-101.5-1.el8_10.s390x.rpm SHA-256: 76bee8517699a10455d655786e8bec6a39af39651162a49def9f7728a41049e1

Red Hat Enterprise Linux for Power, little endian 8

SRPM
osbuild-composer-101.5-1.el8_10.src.rpm SHA-256: 59ecb77d910ce498a80fcbdf17db7556100f4a4afef49452f17867f852291031
ppc64le
osbuild-composer-101.5-1.el8_10.ppc64le.rpm SHA-256: 3e6cf9d8c4ef3f7c94c732dbbb4790457adc8d2b2e4fec6a68bff0b574bc03ba
osbuild-composer-core-101.5-1.el8_10.ppc64le.rpm SHA-256: dc64b717f1b53b2cdffc36bbd9f84cd2ba5bc4927a210efa8ce72f3ad9e4d185
osbuild-composer-core-debuginfo-101.5-1.el8_10.ppc64le.rpm SHA-256: e69f4bce76628bd78b07dbadc1cea9ea13e36b097f1b96c585352057d038b881
osbuild-composer-debuginfo-101.5-1.el8_10.ppc64le.rpm SHA-256: 973ea770bebac721040b3fe436af9c9734b342744c5de57886bf7d3ee834140e
osbuild-composer-debugsource-101.5-1.el8_10.ppc64le.rpm SHA-256: 754c526f58e385b4a75837695f649294fea9fd7c72224021cde8fa9ebd0040f0
osbuild-composer-tests-debuginfo-101.5-1.el8_10.ppc64le.rpm SHA-256: 69acb8e066fffb4611e9df6e42b57b266739f2a5174e0aad5c02c1127b37a021
osbuild-composer-worker-101.5-1.el8_10.ppc64le.rpm SHA-256: ced37fd1f807c7da824d7bc355d669456f15c16c6dfc888fdff9524469cb1f35
osbuild-composer-worker-debuginfo-101.5-1.el8_10.ppc64le.rpm SHA-256: 9b0c1c19ce756977356464142c941d701ddcff1720b5f5cfdbf89e8222a96ac0

Red Hat Enterprise Linux for ARM 64 8

SRPM
osbuild-composer-101.5-1.el8_10.src.rpm SHA-256: 59ecb77d910ce498a80fcbdf17db7556100f4a4afef49452f17867f852291031
aarch64
osbuild-composer-101.5-1.el8_10.aarch64.rpm SHA-256: a96b4f47004e9c0f08f8840b791e1d51d68b188b7d2a0e5bbf22831ac162d010
osbuild-composer-core-101.5-1.el8_10.aarch64.rpm SHA-256: a738eba52171dc856f8a41c850febf38a28bbdc6f5693fe4f9815a9e6ccf2345
osbuild-composer-core-debuginfo-101.5-1.el8_10.aarch64.rpm SHA-256: 6b20064589a7d045a52d6d98594431af975ac9a8f40ec8fc33109f264b326cf1
osbuild-composer-debuginfo-101.5-1.el8_10.aarch64.rpm SHA-256: ee37787d621c09e7be5f057bb1d9e21216ca1d0104dba236f64597655f41d21e
osbuild-composer-debugsource-101.5-1.el8_10.aarch64.rpm SHA-256: 5f94cda95bd2bf710442ec19116e60b5790bb4fe352ef0aec744ad3b0b42e30e
osbuild-composer-tests-debuginfo-101.5-1.el8_10.aarch64.rpm SHA-256: a5e399d402f7799dadf060c768cc3bef21206e1a21912e4b54a5e5c070ffd2af
osbuild-composer-worker-101.5-1.el8_10.aarch64.rpm SHA-256: 5da48567eaea090f95700c4c5a8ebc6dce3a373b6603d51c344868b27ab93201
osbuild-composer-worker-debuginfo-101.5-1.el8_10.aarch64.rpm SHA-256: fae3e935a559798067ba0062f3a47b65abf8eea0b7514017642601969a647b1e

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.5-1.el8_10.src.rpm SHA-256: 59ecb77d910ce498a80fcbdf17db7556100f4a4afef49452f17867f852291031
x86_64
osbuild-composer-101.5-1.el8_10.x86_64.rpm SHA-256: 379afac5f696d619ef2b27573b63c528fadbbc1233928ef612e6dc960b4c7074
osbuild-composer-core-101.5-1.el8_10.x86_64.rpm SHA-256: be2ac777fb8c8062570a68ef80223c660be03b8c7fb9cf354a093a89a3752046
osbuild-composer-core-debuginfo-101.5-1.el8_10.x86_64.rpm SHA-256: 291e39c288c566c27562698662bee30c8668bc1e29c64eeb8253f75debf933f9
osbuild-composer-debuginfo-101.5-1.el8_10.x86_64.rpm SHA-256: bc42fe3eb2e6aabd30e0335f0828076556358e98971df6f071b53db2793b76cc
osbuild-composer-debugsource-101.5-1.el8_10.x86_64.rpm SHA-256: 3ade79319c32b1f954feb1927d1f10d238a4352e8befa26cb957f56c57275704
osbuild-composer-tests-debuginfo-101.5-1.el8_10.x86_64.rpm SHA-256: 6a0dbceeb9e7f9fd659a61f44264d0b4832540da570766c697a6d706b6ffddd7
osbuild-composer-worker-101.5-1.el8_10.x86_64.rpm SHA-256: f130a00386f47db5dea952c1cb8e4e05bde812809682975f7cdb1774c4fd50ff
osbuild-composer-worker-debuginfo-101.5-1.el8_10.x86_64.rpm SHA-256: d9b6ef49cee1ee576c392052fb8bf1f564d7e4e4e0156d5fd6497ac4b3bfe028

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.5-1.el8_10.src.rpm SHA-256: 59ecb77d910ce498a80fcbdf17db7556100f4a4afef49452f17867f852291031
aarch64
osbuild-composer-101.5-1.el8_10.aarch64.rpm SHA-256: a96b4f47004e9c0f08f8840b791e1d51d68b188b7d2a0e5bbf22831ac162d010
osbuild-composer-core-101.5-1.el8_10.aarch64.rpm SHA-256: a738eba52171dc856f8a41c850febf38a28bbdc6f5693fe4f9815a9e6ccf2345
osbuild-composer-core-debuginfo-101.5-1.el8_10.aarch64.rpm SHA-256: 6b20064589a7d045a52d6d98594431af975ac9a8f40ec8fc33109f264b326cf1
osbuild-composer-debuginfo-101.5-1.el8_10.aarch64.rpm SHA-256: ee37787d621c09e7be5f057bb1d9e21216ca1d0104dba236f64597655f41d21e
osbuild-composer-debugsource-101.5-1.el8_10.aarch64.rpm SHA-256: 5f94cda95bd2bf710442ec19116e60b5790bb4fe352ef0aec744ad3b0b42e30e
osbuild-composer-tests-debuginfo-101.5-1.el8_10.aarch64.rpm SHA-256: a5e399d402f7799dadf060c768cc3bef21206e1a21912e4b54a5e5c070ffd2af
osbuild-composer-worker-101.5-1.el8_10.aarch64.rpm SHA-256: 5da48567eaea090f95700c4c5a8ebc6dce3a373b6603d51c344868b27ab93201
osbuild-composer-worker-debuginfo-101.5-1.el8_10.aarch64.rpm SHA-256: fae3e935a559798067ba0062f3a47b65abf8eea0b7514017642601969a647b1e

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.5-1.el8_10.src.rpm SHA-256: 59ecb77d910ce498a80fcbdf17db7556100f4a4afef49452f17867f852291031
ppc64le
osbuild-composer-101.5-1.el8_10.ppc64le.rpm SHA-256: 3e6cf9d8c4ef3f7c94c732dbbb4790457adc8d2b2e4fec6a68bff0b574bc03ba
osbuild-composer-core-101.5-1.el8_10.ppc64le.rpm SHA-256: dc64b717f1b53b2cdffc36bbd9f84cd2ba5bc4927a210efa8ce72f3ad9e4d185
osbuild-composer-core-debuginfo-101.5-1.el8_10.ppc64le.rpm SHA-256: e69f4bce76628bd78b07dbadc1cea9ea13e36b097f1b96c585352057d038b881
osbuild-composer-debuginfo-101.5-1.el8_10.ppc64le.rpm SHA-256: 973ea770bebac721040b3fe436af9c9734b342744c5de57886bf7d3ee834140e
osbuild-composer-debugsource-101.5-1.el8_10.ppc64le.rpm SHA-256: 754c526f58e385b4a75837695f649294fea9fd7c72224021cde8fa9ebd0040f0
osbuild-composer-tests-debuginfo-101.5-1.el8_10.ppc64le.rpm SHA-256: 69acb8e066fffb4611e9df6e42b57b266739f2a5174e0aad5c02c1127b37a021
osbuild-composer-worker-101.5-1.el8_10.ppc64le.rpm SHA-256: ced37fd1f807c7da824d7bc355d669456f15c16c6dfc888fdff9524469cb1f35
osbuild-composer-worker-debuginfo-101.5-1.el8_10.ppc64le.rpm SHA-256: 9b0c1c19ce756977356464142c941d701ddcff1720b5f5cfdbf89e8222a96ac0

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10

SRPM
osbuild-composer-101.5-1.el8_10.src.rpm SHA-256: 59ecb77d910ce498a80fcbdf17db7556100f4a4afef49452f17867f852291031
s390x
osbuild-composer-101.5-1.el8_10.s390x.rpm SHA-256: 38df6b5646a98200f9e169a1b88ccf32823a4ae95e906b90f8528cccf91a71bc
osbuild-composer-core-101.5-1.el8_10.s390x.rpm SHA-256: 41b5fdb397f23fed94cee3aa90bad930d14fbe55a3e9fcf4cfeb7eccaa3c3bfb
osbuild-composer-core-debuginfo-101.5-1.el8_10.s390x.rpm SHA-256: 9ebcd61cfcc9e0c7df2c490f76d78f71243b515278f94fb6041099334c07c67a
osbuild-composer-debuginfo-101.5-1.el8_10.s390x.rpm SHA-256: a28bdbc0abd7c01fc9303f598c8be382132e5d9e785d096a422f01de0e7fc908
osbuild-composer-debugsource-101.5-1.el8_10.s390x.rpm SHA-256: fd3e5b32fd1b73feb72ce1f2c817f5792b18e95daeb95339c29f3082fc65e204
osbuild-composer-tests-debuginfo-101.5-1.el8_10.s390x.rpm SHA-256: 4257f6d71e61ed57173e03794e39e078f429c93abfd3fd50beca61d2e0980fc0
osbuild-composer-worker-101.5-1.el8_10.s390x.rpm SHA-256: 44fa30678f48c6ae406ee87ba695d2c46b9217268df59b392a778b7b79b71eed
osbuild-composer-worker-debuginfo-101.5-1.el8_10.s390x.rpm SHA-256: 76bee8517699a10455d655786e8bec6a39af39651162a49def9f7728a41049e1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility