RHSA-2026:55525: Moderate: butane security update
Butane translates human-readable Butane Configs into machine-readable Ignition configs for provisioning operating systems that use Ignition.Security Fix(es): golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/butaneto a version that resolves this vulnerability.Fixed in 0.17.0-1.el9_2.1 - Upgrade
Upgrade
redhat/butane-debuginfoto a version that resolves this vulnerability.Fixed in 0.17.0-1.el9_2.1 - Upgrade
Upgrade
redhat/butane-debugsourceto a version that resolves this vulnerability.Fixed in 0.17.0-1.el9_2.1 - Upgrade
Upgrade
redhat/butaneto a version that resolves this vulnerability.Fixed in 0.17.0-1.el9_2.1.aa - Upgrade
Upgrade
redhat/butane-debuginfoto a version that resolves this vulnerability.Fixed in 0.17.0-1.el9_2.1.aa - Upgrade
Upgrade
redhat/butane-debugsourceto a version that resolves this vulnerability.Fixed in 0.17.0-1.el9_2.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:55525?
The severity of RHSA-2026:55525 is classified as medium with a score of 4.
What security issue is addressed by RHSA-2026:55525?
RHSA-2026:55525 addresses the Golang FIPS zeroed buffer vulnerability identified as CVE-2024-9355.
How do I fix RHSA-2026:55525?
To fix RHSA-2026:55525, you should apply the latest security update for Butane provided by Red Hat.
What software packages are affected by RHSA-2026:55525?
The affected software packages include redhat/butane, redhat/butane-debuginfo, and redhat/butane-debugsource, among others.
When was RHSA-2026:55525 published?
RHSA-2026:55525 was published on August 17, 2026.