Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:52389 - Security Advisory
Issued:
2026-08-10
Updated:
2026-08-10

RHSA-2026:52389 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url

CVEs

  • CVE-2026-25679

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8

SRPM
osbuild-composer-75-9.el8_8.src.rpm SHA-256: dbde58e58d3caf3cab789bcbc88da8802b8cc06f1cf53a6e20ccab77f82f1318
x86_64
osbuild-composer-75-9.el8_8.x86_64.rpm SHA-256: a95c84343d936b25e5a15c00448c3de73aac46bcd290fcb0e087e85387d7681b
osbuild-composer-core-75-9.el8_8.x86_64.rpm SHA-256: fb993267cbb3cbd860d68ced57e6d6b99d94c286e5f98b40e78d8140fe3e4783
osbuild-composer-core-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 7d2ffa5b592879970cedb1b887f81d65ca4b1bf9d96aafc63ec765e2c401c4c2
osbuild-composer-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 5533d9abe9a7b1c9d7358feec2d6d0bdfe94a77f7fd58667b707d41cfecaa58f
osbuild-composer-debugsource-75-9.el8_8.x86_64.rpm SHA-256: da9f36cc3b7ccd149259c428d67c4eb7b18c2af8f5ce82a963d3011b06136426
osbuild-composer-dnf-json-75-9.el8_8.x86_64.rpm SHA-256: 1278d0ebc007ba5008d271c098b69d85f718e5f3f0876a72e80e42f216e8078c
osbuild-composer-tests-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: d163c0e9db1d0a10f3790b81a0c83b9585358d78a57b5ba0c62855f820d4b5c6
osbuild-composer-worker-75-9.el8_8.x86_64.rpm SHA-256: 6326b1f2aaa4e34e4d4e7d07c1e747d780a5afd53a73a6420c6c37d433f703fb
osbuild-composer-worker-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 8e193e04a8bdb844624119944e65b2e7d23ba5bc5eba409e24cc2171809d33b7

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
osbuild-composer-75-9.el8_8.src.rpm SHA-256: dbde58e58d3caf3cab789bcbc88da8802b8cc06f1cf53a6e20ccab77f82f1318
x86_64
osbuild-composer-75-9.el8_8.x86_64.rpm SHA-256: a95c84343d936b25e5a15c00448c3de73aac46bcd290fcb0e087e85387d7681b
osbuild-composer-core-75-9.el8_8.x86_64.rpm SHA-256: fb993267cbb3cbd860d68ced57e6d6b99d94c286e5f98b40e78d8140fe3e4783
osbuild-composer-core-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 7d2ffa5b592879970cedb1b887f81d65ca4b1bf9d96aafc63ec765e2c401c4c2
osbuild-composer-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 5533d9abe9a7b1c9d7358feec2d6d0bdfe94a77f7fd58667b707d41cfecaa58f
osbuild-composer-debugsource-75-9.el8_8.x86_64.rpm SHA-256: da9f36cc3b7ccd149259c428d67c4eb7b18c2af8f5ce82a963d3011b06136426
osbuild-composer-dnf-json-75-9.el8_8.x86_64.rpm SHA-256: 1278d0ebc007ba5008d271c098b69d85f718e5f3f0876a72e80e42f216e8078c
osbuild-composer-tests-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: d163c0e9db1d0a10f3790b81a0c83b9585358d78a57b5ba0c62855f820d4b5c6
osbuild-composer-worker-75-9.el8_8.x86_64.rpm SHA-256: 6326b1f2aaa4e34e4d4e7d07c1e747d780a5afd53a73a6420c6c37d433f703fb
osbuild-composer-worker-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 8e193e04a8bdb844624119944e65b2e7d23ba5bc5eba409e24cc2171809d33b7

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
osbuild-composer-75-9.el8_8.src.rpm SHA-256: dbde58e58d3caf3cab789bcbc88da8802b8cc06f1cf53a6e20ccab77f82f1318
ppc64le
osbuild-composer-75-9.el8_8.ppc64le.rpm SHA-256: a22f34d3fc59ef8aa747544b91c4b1916dac1d35c94325f49776b8f8a096b739
osbuild-composer-core-75-9.el8_8.ppc64le.rpm SHA-256: 9e850548dd031cc86f0c71a1ba048447929e16735dfa0afe36c24e9daafbc164
osbuild-composer-core-debuginfo-75-9.el8_8.ppc64le.rpm SHA-256: 7bcd6555b8bbb8a687544f0f3fcb0f96f7af4c26b2fe7010ffc6f8bbb373913b
osbuild-composer-debuginfo-75-9.el8_8.ppc64le.rpm SHA-256: c138ca5e322eb832119cea58586fd706f5098e85cb51583268dfa2b3b720a716
osbuild-composer-debugsource-75-9.el8_8.ppc64le.rpm SHA-256: 83601215df3f6c2f8e68f90c9607c0bc0f1b04a5c5e5f91d7c40436f443fb1a9
osbuild-composer-dnf-json-75-9.el8_8.ppc64le.rpm SHA-256: 3e094cd6c8a97259e949f024071036402553482e751d758c61272b920bd9be55
osbuild-composer-tests-debuginfo-75-9.el8_8.ppc64le.rpm SHA-256: 63b9c65324e793fa26ac74f24ded57549e35f0397d05cf8a7a2d0444e3a1334c
osbuild-composer-worker-75-9.el8_8.ppc64le.rpm SHA-256: 081d7118696f84b3c384cbcc1adde01edcf910620adb583c5d7a52b32fd3d79d
osbuild-composer-worker-debuginfo-75-9.el8_8.ppc64le.rpm SHA-256: 02b6858c9ff8ab7525d8662875cf8383058ff46a6aaf8a672c0c5bb1fe5d4574

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
osbuild-composer-75-9.el8_8.src.rpm SHA-256: dbde58e58d3caf3cab789bcbc88da8802b8cc06f1cf53a6e20ccab77f82f1318
x86_64
osbuild-composer-75-9.el8_8.x86_64.rpm SHA-256: a95c84343d936b25e5a15c00448c3de73aac46bcd290fcb0e087e85387d7681b
osbuild-composer-core-75-9.el8_8.x86_64.rpm SHA-256: fb993267cbb3cbd860d68ced57e6d6b99d94c286e5f98b40e78d8140fe3e4783
osbuild-composer-core-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 7d2ffa5b592879970cedb1b887f81d65ca4b1bf9d96aafc63ec765e2c401c4c2
osbuild-composer-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 5533d9abe9a7b1c9d7358feec2d6d0bdfe94a77f7fd58667b707d41cfecaa58f
osbuild-composer-debugsource-75-9.el8_8.x86_64.rpm SHA-256: da9f36cc3b7ccd149259c428d67c4eb7b18c2af8f5ce82a963d3011b06136426
osbuild-composer-dnf-json-75-9.el8_8.x86_64.rpm SHA-256: 1278d0ebc007ba5008d271c098b69d85f718e5f3f0876a72e80e42f216e8078c
osbuild-composer-tests-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: d163c0e9db1d0a10f3790b81a0c83b9585358d78a57b5ba0c62855f820d4b5c6
osbuild-composer-worker-75-9.el8_8.x86_64.rpm SHA-256: 6326b1f2aaa4e34e4d4e7d07c1e747d780a5afd53a73a6420c6c37d433f703fb
osbuild-composer-worker-debuginfo-75-9.el8_8.x86_64.rpm SHA-256: 8e193e04a8bdb844624119944e65b2e7d23ba5bc5eba409e24cc2171809d33b7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility