Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5327 - Security Advisory
Issued:
2026-03-23
Updated:
2026-03-23

RHSA-2026:5327 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
  • BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url

CVEs

  • CVE-2025-61726
  • CVE-2025-61729

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
osbuild-composer-76.1-5.el9_2.src.rpm SHA-256: 7b3994ba8513c78dca1cff3dfc8ebf3035a8476a74237f04909f3915eaf1f1c2
x86_64
osbuild-composer-76.1-5.el9_2.x86_64.rpm SHA-256: 5acdbba124f51107c1c253336f6896aef9629ca0aadfe64655d09149f632ac71
osbuild-composer-core-76.1-5.el9_2.x86_64.rpm SHA-256: 4e266032c838e39b9e909c06fc94e96a2c69666f7f212b7b876730a309c371a0
osbuild-composer-core-debuginfo-76.1-5.el9_2.x86_64.rpm SHA-256: 86942cb109f697fc351cbf8d578c557de95cfa59db223137b1820552f4d0de65
osbuild-composer-debuginfo-76.1-5.el9_2.x86_64.rpm SHA-256: 1d2e24492c5dbacc84341d042ff70e8a2dc56376ddcb89ff7e675d17d4cd9d07
osbuild-composer-debugsource-76.1-5.el9_2.x86_64.rpm SHA-256: 91e38410f1a8e351749ae0513d888d437ae511cdb5704fbfdbf77499207ea6cb
osbuild-composer-dnf-json-76.1-5.el9_2.x86_64.rpm SHA-256: 6e0fee6dc5f2fd2259cc19bf34b1354939cc3a85634dd5ccd8b7f2e5b45249e7
osbuild-composer-tests-debuginfo-76.1-5.el9_2.x86_64.rpm SHA-256: d31729d3667783ecab5f7a18768f7fe6927eb545873153180557003c0b16f80f
osbuild-composer-worker-76.1-5.el9_2.x86_64.rpm SHA-256: c8dcb703e7316cb548e60c34420b6a37ea18ec6d02c9eb47fd04bf31143eda98
osbuild-composer-worker-debuginfo-76.1-5.el9_2.x86_64.rpm SHA-256: ae6574cae25451c260578efe6bc4f4c1c4441bef9b10b1937275ca15d7956b5c

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
osbuild-composer-76.1-5.el9_2.src.rpm SHA-256: 7b3994ba8513c78dca1cff3dfc8ebf3035a8476a74237f04909f3915eaf1f1c2
ppc64le
osbuild-composer-76.1-5.el9_2.ppc64le.rpm SHA-256: 8641fd36c815c6573026f44a759ee0adc1aa1cf7f01017362c9b213a6bc5dd16
osbuild-composer-core-76.1-5.el9_2.ppc64le.rpm SHA-256: c3df8d6fa27a5063e9b628ee6c3de31df40afb09922058aff1ce1a7cbbacb82b
osbuild-composer-core-debuginfo-76.1-5.el9_2.ppc64le.rpm SHA-256: 6a4247f2c919e255e81984a4d704e2c8e9d9d4e01f3d67059c6114561acd281d
osbuild-composer-debuginfo-76.1-5.el9_2.ppc64le.rpm SHA-256: f11823c34631331371a936c2c1a32aa11fd0588d20f8f8114b0ab3f3be86aafe
osbuild-composer-debugsource-76.1-5.el9_2.ppc64le.rpm SHA-256: 11881369191b5c07efac67cef2ec7b6252bbc8be2cc4de1abef0c0ad1aab95c6
osbuild-composer-dnf-json-76.1-5.el9_2.ppc64le.rpm SHA-256: 8a6b6ccd2e1ef45d20d67ec23a662c9a4aab79add365dfbc7e667e7726c245dc
osbuild-composer-tests-debuginfo-76.1-5.el9_2.ppc64le.rpm SHA-256: 475592b2267dfebbbf1e83a9f2f6080d169a7546ecd4b71ea4b9ee31a7c59a2f
osbuild-composer-worker-76.1-5.el9_2.ppc64le.rpm SHA-256: 3751a81e3c5b26dbf7b68cb8b354ed310b1e423cc06e57bad9c2b4a8df156615
osbuild-composer-worker-debuginfo-76.1-5.el9_2.ppc64le.rpm SHA-256: a447f458b7435a8d81db60eaaa3c84839b9da701a207dba85fa93d1f138ab438

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
osbuild-composer-76.1-5.el9_2.src.rpm SHA-256: 7b3994ba8513c78dca1cff3dfc8ebf3035a8476a74237f04909f3915eaf1f1c2
x86_64
osbuild-composer-76.1-5.el9_2.x86_64.rpm SHA-256: 5acdbba124f51107c1c253336f6896aef9629ca0aadfe64655d09149f632ac71
osbuild-composer-core-76.1-5.el9_2.x86_64.rpm SHA-256: 4e266032c838e39b9e909c06fc94e96a2c69666f7f212b7b876730a309c371a0
osbuild-composer-core-debuginfo-76.1-5.el9_2.x86_64.rpm SHA-256: 86942cb109f697fc351cbf8d578c557de95cfa59db223137b1820552f4d0de65
osbuild-composer-debuginfo-76.1-5.el9_2.x86_64.rpm SHA-256: 1d2e24492c5dbacc84341d042ff70e8a2dc56376ddcb89ff7e675d17d4cd9d07
osbuild-composer-debugsource-76.1-5.el9_2.x86_64.rpm SHA-256: 91e38410f1a8e351749ae0513d888d437ae511cdb5704fbfdbf77499207ea6cb
osbuild-composer-dnf-json-76.1-5.el9_2.x86_64.rpm SHA-256: 6e0fee6dc5f2fd2259cc19bf34b1354939cc3a85634dd5ccd8b7f2e5b45249e7
osbuild-composer-tests-debuginfo-76.1-5.el9_2.x86_64.rpm SHA-256: d31729d3667783ecab5f7a18768f7fe6927eb545873153180557003c0b16f80f
osbuild-composer-worker-76.1-5.el9_2.x86_64.rpm SHA-256: c8dcb703e7316cb548e60c34420b6a37ea18ec6d02c9eb47fd04bf31143eda98
osbuild-composer-worker-debuginfo-76.1-5.el9_2.x86_64.rpm SHA-256: ae6574cae25451c260578efe6bc4f4c1c4441bef9b10b1937275ca15d7956b5c

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
osbuild-composer-76.1-5.el9_2.src.rpm SHA-256: 7b3994ba8513c78dca1cff3dfc8ebf3035a8476a74237f04909f3915eaf1f1c2
aarch64
osbuild-composer-76.1-5.el9_2.aarch64.rpm SHA-256: 0446cfdf599f5fb2ff0c4555b64fed2bfdc5c3855679db08af062616f125a18d
osbuild-composer-core-76.1-5.el9_2.aarch64.rpm SHA-256: 9a577cd2739fd8a1b617039633db7a083b203c86db593099aaf3aad9e6e4601f
osbuild-composer-core-debuginfo-76.1-5.el9_2.aarch64.rpm SHA-256: 0fab6d6050f0e065273e66b95ae7a59027d24212d3f2f9e5a0076f3ad13a9ca0
osbuild-composer-debuginfo-76.1-5.el9_2.aarch64.rpm SHA-256: 70427cab0c5718d39d2d3fd0ed3919a71ac8be5f6b69ba6c860a75e5f8710a31
osbuild-composer-debugsource-76.1-5.el9_2.aarch64.rpm SHA-256: 7095f17e7dc3dae83402e32b1b659a246ef4dd28dbbc0465021dc6019ff7e721
osbuild-composer-dnf-json-76.1-5.el9_2.aarch64.rpm SHA-256: f9f1d6c0fd6b32781d595695960528ab11667bf8737428df56fe801afdebe8a0
osbuild-composer-tests-debuginfo-76.1-5.el9_2.aarch64.rpm SHA-256: e228a540e37933e24c16e638ddaca29a3380b3036528ffd6269bc7c3b893c8be
osbuild-composer-worker-76.1-5.el9_2.aarch64.rpm SHA-256: 1d5cdd1a576faf472c1bc52b5c29ad5868f5e7eae59e04eea804710ce2dfbf18
osbuild-composer-worker-debuginfo-76.1-5.el9_2.aarch64.rpm SHA-256: 6a18bbcdb3bd6235d1f00921fc3e2516f7b11c4d6c7a7fa192af3ce230b3db56

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
osbuild-composer-76.1-5.el9_2.src.rpm SHA-256: 7b3994ba8513c78dca1cff3dfc8ebf3035a8476a74237f04909f3915eaf1f1c2
s390x
osbuild-composer-76.1-5.el9_2.s390x.rpm SHA-256: 46287f0a0e8a07e35f477a437dbd0cd7f72494ff5aeae586c615b89bb7edf16f
osbuild-composer-core-76.1-5.el9_2.s390x.rpm SHA-256: d5661d60e426708546bcab2dbbf5d3b9d4dacd142cf8c4698413737f5c8edd23
osbuild-composer-core-debuginfo-76.1-5.el9_2.s390x.rpm SHA-256: 6725c776d1f599b8528ca2c20636dde7b3d3d3b132a2ed310ed4cfaa4173cc11
osbuild-composer-debuginfo-76.1-5.el9_2.s390x.rpm SHA-256: 308ce1607fcf2ced552ebb64706a542ac5619a5fa7909e11fde9119c8342da01
osbuild-composer-debugsource-76.1-5.el9_2.s390x.rpm SHA-256: 9ce0db4ce7b09fd6abf88ac35c41501b5df86c8291644751dfaff3d31c19cba4
osbuild-composer-dnf-json-76.1-5.el9_2.s390x.rpm SHA-256: 2513c50dc08c655e78759108c72ca6a55b1ea60dc4594786bc23153b481cbf5e
osbuild-composer-tests-debuginfo-76.1-5.el9_2.s390x.rpm SHA-256: 0b6faddeaef8aa17cfda1a984787fc2da27e742ee32ca9e28f4740c126ced4e5
osbuild-composer-worker-76.1-5.el9_2.s390x.rpm SHA-256: 2f3456324593e517a6a5878566d66684a383666f4be01dff9509c2d62256362a
osbuild-composer-worker-debuginfo-76.1-5.el9_2.s390x.rpm SHA-256: dade151eb0de074b4fefe590f7fc3228d7ab7107d2f76d7533d31177cc483f36

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility