Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5852 - Security Advisory
Issued:
2026-03-26
Updated:
2026-03-26

RHSA-2026:5852 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: osbuild-composer security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for osbuild-composer is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.

Security Fix(es):

  • crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64

Fixes

  • BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
  • BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url

CVEs

  • CVE-2025-61726
  • CVE-2025-61729

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-5.el10_0.src.rpm SHA-256: 514a0482c4bc501160978e2e2b6695bf4bdd6bd73d7096d5150318140f92ffb0
x86_64
osbuild-composer-134.1-5.el10_0.x86_64.rpm SHA-256: 78fe75f957837d41065488463e18639688bfd3493a49738fb5828dbf078f335d
osbuild-composer-core-134.1-5.el10_0.x86_64.rpm SHA-256: a1cc5b747482d913b5c0ea5087861adf8dd4f029a1729b32981bfd37d77f0b3b
osbuild-composer-core-debuginfo-134.1-5.el10_0.x86_64.rpm SHA-256: 5bf6103703cbe267652a7ef46b7b7b63d7e76e4ef0ccd7b24d1e8c49a8ebf265
osbuild-composer-debugsource-134.1-5.el10_0.x86_64.rpm SHA-256: c700913e6836c619d9e94723af16ef9fe92a9b579de96a8ab6bc14f696ff2f89
osbuild-composer-tests-debuginfo-134.1-5.el10_0.x86_64.rpm SHA-256: a9f2ac004439afe08cb61a7cd0e61cf9a9b452be20fd57d0c947bf411ee69a6d
osbuild-composer-worker-134.1-5.el10_0.x86_64.rpm SHA-256: ddcfc4d1f3849c72e3ffe99ccc806db1ced454d2208781b4ff51c972cf31bbe4
osbuild-composer-worker-debuginfo-134.1-5.el10_0.x86_64.rpm SHA-256: 3f03a4ff449d1a21e7b47cb1666e7d511118939abcbb7a494b31223d524f2aaa

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-5.el10_0.src.rpm SHA-256: 514a0482c4bc501160978e2e2b6695bf4bdd6bd73d7096d5150318140f92ffb0
s390x
osbuild-composer-134.1-5.el10_0.s390x.rpm SHA-256: 4f2d5763bcbb35ffaffa03f277db809b288c1341d7800d92bc0882ed01cb9014
osbuild-composer-core-134.1-5.el10_0.s390x.rpm SHA-256: 828734a4f4f02ead6875040395190a4d6a2906146baa1fe67b2917323826d266
osbuild-composer-core-debuginfo-134.1-5.el10_0.s390x.rpm SHA-256: 8e5095462592f95097306d087cda0bc6e29994d57c21c368e379a8869e2f8ca7
osbuild-composer-debugsource-134.1-5.el10_0.s390x.rpm SHA-256: bdeeb0cc5405eb46ec2c2891a3fab0eb5d5e0a073c1e01d194636ef602eb63e2
osbuild-composer-tests-debuginfo-134.1-5.el10_0.s390x.rpm SHA-256: 24dd95b1399733a1dce24f3ceba44ef86ed0e00884226ed406d1c567c3e56362
osbuild-composer-worker-134.1-5.el10_0.s390x.rpm SHA-256: 2379e0c76c62b810c713ff687722c3cc1a5a557e003b61f4c9aaec281e811dc8
osbuild-composer-worker-debuginfo-134.1-5.el10_0.s390x.rpm SHA-256: 7701c0271586e492aad3b9e8e752df6e64317c59f7da76dbba55af2e25faad58

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-5.el10_0.src.rpm SHA-256: 514a0482c4bc501160978e2e2b6695bf4bdd6bd73d7096d5150318140f92ffb0
ppc64le
osbuild-composer-134.1-5.el10_0.ppc64le.rpm SHA-256: fc1d23a7128eb0b9ee7f52a32bf1c70f84f1e19421ec7284156a1ab4e7f2502c
osbuild-composer-core-134.1-5.el10_0.ppc64le.rpm SHA-256: 661f2bfa73433cf6c33398c245bfdb6e30c615990e5d656600295c4ebd0807b4
osbuild-composer-core-debuginfo-134.1-5.el10_0.ppc64le.rpm SHA-256: cb1386835eeb252bee923e4133f60815b5c35ef67c199f031e843516fbbd836c
osbuild-composer-debugsource-134.1-5.el10_0.ppc64le.rpm SHA-256: bc791a4666a0738b4cbe69d42165c8c3eeacf060aa4d01c172f57e33ee1fa812
osbuild-composer-tests-debuginfo-134.1-5.el10_0.ppc64le.rpm SHA-256: 4bb11be9dfe7a317e53fa4ba5fdfd72f5446e0c77d745d97f5a5f9f43f61aba9
osbuild-composer-worker-134.1-5.el10_0.ppc64le.rpm SHA-256: 3064825bcb6d06b538a9614b350cf78fa34914fc07fef271d36b8b039171532b
osbuild-composer-worker-debuginfo-134.1-5.el10_0.ppc64le.rpm SHA-256: 96bc5f76643fca38446192abf711b5a2ee2a05502444cdd34d06d7549947aa25

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0

SRPM
osbuild-composer-134.1-5.el10_0.src.rpm SHA-256: 514a0482c4bc501160978e2e2b6695bf4bdd6bd73d7096d5150318140f92ffb0
aarch64
osbuild-composer-134.1-5.el10_0.aarch64.rpm SHA-256: 3c6c7a8f232b8ec0ce013644759cfdaede1d30a28a911b0de766494af8d7731a
osbuild-composer-core-134.1-5.el10_0.aarch64.rpm SHA-256: d83dc32975332af2e038f4050722269b636dd53e4932aa33e2408758fd908c07
osbuild-composer-core-debuginfo-134.1-5.el10_0.aarch64.rpm SHA-256: e2083eb34ac7684282ab43be2349437cd5f3c2a4140ac9ed58843369893a7d0e
osbuild-composer-debugsource-134.1-5.el10_0.aarch64.rpm SHA-256: b563a90b0770925b056273366e3fcd573270fc001514a33b7153cca0e2facb84
osbuild-composer-tests-debuginfo-134.1-5.el10_0.aarch64.rpm SHA-256: ae2854f893789e5869b1676d9ff41ca2c9ea9d5bb2b96e5447b509e934574fff
osbuild-composer-worker-134.1-5.el10_0.aarch64.rpm SHA-256: c4278d11cbe05343a5937a44bf6d7c0dc0b5ee3d8fe1d53274c298b73a4671b2
osbuild-composer-worker-debuginfo-134.1-5.el10_0.aarch64.rpm SHA-256: 8a1cb10d1e26a3f2fd6f4136080c9afbe2fa4c5c3afc19d7072c6e4b91d15487

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-5.el10_0.src.rpm SHA-256: 514a0482c4bc501160978e2e2b6695bf4bdd6bd73d7096d5150318140f92ffb0
aarch64
osbuild-composer-134.1-5.el10_0.aarch64.rpm SHA-256: 3c6c7a8f232b8ec0ce013644759cfdaede1d30a28a911b0de766494af8d7731a
osbuild-composer-core-134.1-5.el10_0.aarch64.rpm SHA-256: d83dc32975332af2e038f4050722269b636dd53e4932aa33e2408758fd908c07
osbuild-composer-core-debuginfo-134.1-5.el10_0.aarch64.rpm SHA-256: e2083eb34ac7684282ab43be2349437cd5f3c2a4140ac9ed58843369893a7d0e
osbuild-composer-debugsource-134.1-5.el10_0.aarch64.rpm SHA-256: b563a90b0770925b056273366e3fcd573270fc001514a33b7153cca0e2facb84
osbuild-composer-tests-debuginfo-134.1-5.el10_0.aarch64.rpm SHA-256: ae2854f893789e5869b1676d9ff41ca2c9ea9d5bb2b96e5447b509e934574fff
osbuild-composer-worker-134.1-5.el10_0.aarch64.rpm SHA-256: c4278d11cbe05343a5937a44bf6d7c0dc0b5ee3d8fe1d53274c298b73a4671b2
osbuild-composer-worker-debuginfo-134.1-5.el10_0.aarch64.rpm SHA-256: 8a1cb10d1e26a3f2fd6f4136080c9afbe2fa4c5c3afc19d7072c6e4b91d15487

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-5.el10_0.src.rpm SHA-256: 514a0482c4bc501160978e2e2b6695bf4bdd6bd73d7096d5150318140f92ffb0
s390x
osbuild-composer-134.1-5.el10_0.s390x.rpm SHA-256: 4f2d5763bcbb35ffaffa03f277db809b288c1341d7800d92bc0882ed01cb9014
osbuild-composer-core-134.1-5.el10_0.s390x.rpm SHA-256: 828734a4f4f02ead6875040395190a4d6a2906146baa1fe67b2917323826d266
osbuild-composer-core-debuginfo-134.1-5.el10_0.s390x.rpm SHA-256: 8e5095462592f95097306d087cda0bc6e29994d57c21c368e379a8869e2f8ca7
osbuild-composer-debugsource-134.1-5.el10_0.s390x.rpm SHA-256: bdeeb0cc5405eb46ec2c2891a3fab0eb5d5e0a073c1e01d194636ef602eb63e2
osbuild-composer-tests-debuginfo-134.1-5.el10_0.s390x.rpm SHA-256: 24dd95b1399733a1dce24f3ceba44ef86ed0e00884226ed406d1c567c3e56362
osbuild-composer-worker-134.1-5.el10_0.s390x.rpm SHA-256: 2379e0c76c62b810c713ff687722c3cc1a5a557e003b61f4c9aaec281e811dc8
osbuild-composer-worker-debuginfo-134.1-5.el10_0.s390x.rpm SHA-256: 7701c0271586e492aad3b9e8e752df6e64317c59f7da76dbba55af2e25faad58

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0

SRPM
osbuild-composer-134.1-5.el10_0.src.rpm SHA-256: 514a0482c4bc501160978e2e2b6695bf4bdd6bd73d7096d5150318140f92ffb0
ppc64le
osbuild-composer-134.1-5.el10_0.ppc64le.rpm SHA-256: fc1d23a7128eb0b9ee7f52a32bf1c70f84f1e19421ec7284156a1ab4e7f2502c
osbuild-composer-core-134.1-5.el10_0.ppc64le.rpm SHA-256: 661f2bfa73433cf6c33398c245bfdb6e30c615990e5d656600295c4ebd0807b4
osbuild-composer-core-debuginfo-134.1-5.el10_0.ppc64le.rpm SHA-256: cb1386835eeb252bee923e4133f60815b5c35ef67c199f031e843516fbbd836c
osbuild-composer-debugsource-134.1-5.el10_0.ppc64le.rpm SHA-256: bc791a4666a0738b4cbe69d42165c8c3eeacf060aa4d01c172f57e33ee1fa812
osbuild-composer-tests-debuginfo-134.1-5.el10_0.ppc64le.rpm SHA-256: 4bb11be9dfe7a317e53fa4ba5fdfd72f5446e0c77d745d97f5a5f9f43f61aba9
osbuild-composer-worker-134.1-5.el10_0.ppc64le.rpm SHA-256: 3064825bcb6d06b538a9614b350cf78fa34914fc07fef271d36b8b039171532b
osbuild-composer-worker-debuginfo-134.1-5.el10_0.ppc64le.rpm SHA-256: 96bc5f76643fca38446192abf711b5a2ee2a05502444cdd34d06d7549947aa25

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0

SRPM
osbuild-composer-134.1-5.el10_0.src.rpm SHA-256: 514a0482c4bc501160978e2e2b6695bf4bdd6bd73d7096d5150318140f92ffb0
x86_64
osbuild-composer-134.1-5.el10_0.x86_64.rpm SHA-256: 78fe75f957837d41065488463e18639688bfd3493a49738fb5828dbf078f335d
osbuild-composer-core-134.1-5.el10_0.x86_64.rpm SHA-256: a1cc5b747482d913b5c0ea5087861adf8dd4f029a1729b32981bfd37d77f0b3b
osbuild-composer-core-debuginfo-134.1-5.el10_0.x86_64.rpm SHA-256: 5bf6103703cbe267652a7ef46b7b7b63d7e76e4ef0ccd7b24d1e8c49a8ebf265
osbuild-composer-debugsource-134.1-5.el10_0.x86_64.rpm SHA-256: c700913e6836c619d9e94723af16ef9fe92a9b579de96a8ab6bc14f696ff2f89
osbuild-composer-tests-debuginfo-134.1-5.el10_0.x86_64.rpm SHA-256: a9f2ac004439afe08cb61a7cd0e61cf9a9b452be20fd57d0c947bf411ee69a6d
osbuild-composer-worker-134.1-5.el10_0.x86_64.rpm SHA-256: ddcfc4d1f3849c72e3ffe99ccc806db1ced454d2208781b4ff51c972cf31bbe4
osbuild-composer-worker-debuginfo-134.1-5.el10_0.x86_64.rpm SHA-256: 3f03a4ff449d1a21e7b47cb1666e7d511118939abcbb7a494b31223d524f2aaa

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility