RHSA-2026:55520: Moderate: butane security update
Butane translates human-readable Butane Configs into machine-readable Ignition configs for provisioning operating systems that use Ignition.Security Fix(es): golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/butaneto a version that resolves this vulnerability.Fixed in 0.23.0-1.el9_6.1 - Upgrade
Upgrade
redhat/butane-debuginfoto a version that resolves this vulnerability.Fixed in 0.23.0-1.el9_6.1 - Upgrade
Upgrade
redhat/butane-debugsourceto a version that resolves this vulnerability.Fixed in 0.23.0-1.el9_6.1 - Upgrade
Upgrade
redhat/butaneto a version that resolves this vulnerability.Fixed in 0.23.0-1.el9_6.1.aa - Upgrade
Upgrade
redhat/butane-debuginfoto a version that resolves this vulnerability.Fixed in 0.23.0-1.el9_6.1.aa - Upgrade
Upgrade
redhat/butane-debugsourceto a version that resolves this vulnerability.Fixed in 0.23.0-1.el9_6.1.aa - Upgrade
Upgrade
golang-fipsto a version that resolves this vulnerability.Patch CVE-2024-9355
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:55520?
The severity of RHSA-2026:55520 is classified as medium with a CVSS score of 4.
How do I fix RHSA-2026:55520?
To fix RHSA-2026:55520, you need to update the affected Butane packages to the latest version provided by Red Hat.
What software is affected by RHSA-2026:55520?
The affected software includes redhat/butane, redhat/butane-debuginfo, redhat/butane-debugsource, and multiple Red Hat Enterprise Linux variants.
What is the main security issue addressed in RHSA-2026:55520?
The main security issue addressed in RHSA-2026:55520 is the Golang FIPS zeroed buffer vulnerability, identified by CVE-2024-9355.
When was RHSA-2026:55520 published?
RHSA-2026:55520 was published on August 17, 2026.