RHSA-2025:21628: Critical: lasso security update
Critical: lasso security update
Other sources
The lasso packages provide the Lasso library that implements the Liberty Alliance Single Sign-On standards, including the SAML and SAML2 specifications. It allows handling of the whole life-cycle of SAML-based federations and provides bindings for multiple languages.Security Fix(es): lasso: Type confusion in Entr'ouvert Lasso (CVE-2025-47151) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:21628?
RHSA-2025:21628 is classified as a critical vulnerability.
How do I fix RHSA-2025:21628?
To address RHSA-2025:21628, you should update the lasso package to version 2.6.0-14.el8_10.
Which packages are affected by RHSA-2025:21628?
RHSA-2025:21628 affects various lasso packages across multiple architectures including x86_64, ARM 64, Power, and IBM z Systems.
What does the lasso library do in relation to RHSA-2025:21628?
The lasso library implements the Liberty Alliance Single Sign-On standards, which includes SAML and SAML2 specifications.
Is there a need for a system reboot after applying the fix for RHSA-2025:21628?
A reboot may be required after updating to ensure that all services using the lasso library are restarted with the patched version.