RHSA-2025:9148: Moderate: buildah security update
Moderate: buildah security update
Other sources
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): net/http: Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:9148?
The severity of RHSA-2025:9148 is categorized as moderate.
How do I fix RHSA-2025:9148?
To fix RHSA-2025:9148, update the package 'buildah' to version 1.39.4-2.el10_0 or later.
Which products are affected by RHSA-2025:9148?
RHSA-2025:9148 affects various versions of Red Hat Enterprise Linux across multiple architectures including IBM z Systems, Power little endian, and ARM 64.
What is the recommended version to mitigate RHSA-2025:9148?
The recommended version to mitigate RHSA-2025:9148 is buildah version 1.39.4-2.el10_0.
Are there any dependencies to consider with RHSA-2025:9148?
Yes, ensure that related buildah packages such as buildah-debuginfo, buildah-debugsource, and buildah-tests are also updated to the remedied version.