RHSA-2025:9623: Moderate: osbuild-composer security update
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.Security Fix(es): net/http: Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: osbuild-composer security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems and components are covered by this update?
Systems using the listed Red Hat osbuild-composer packages are in scope, including the core and worker components. The advisory specifically identifies Red Hat Enterprise Linux for IBM z Systems with 4 years of updates.
What is known about exploitation conditions and temporary mitigations?
The issue is a request-smuggling vulnerability in Go's net/http handling of invalid chunked data. The advisory does not specify the attacker’s required access, affected default configuration, or any compensating controls.
What should be done to remediate the issue?
Apply the advisory update using Red Hat’s update instructions referenced by the advisory. No fixed package version is provided in the available information.