RHSA-2026:52391: Important: osbuild-composer security update
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.Security Fix(es): net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: osbuild-composer security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/osbuild-composerto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
redhat/osbuild-composer-coreto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
redhat/osbuild-composer-core-debuginfoto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
redhat/osbuild-composer-debuginfoto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
redhat/osbuild-composer-debugsourceto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
redhat/osbuild-composer-dnf-jsonto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
redhat/osbuild-composer-tests-debuginfoto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
redhat/osbuild-composer-workerto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
redhat/osbuild-composer-worker-debuginfoto a version that resolves this vulnerability.Fixed in 46.3-7.el8_6 - Upgrade
Upgrade
osbuild-composerto a version that resolves this vulnerability.Patch CVE-2026-25679
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52391?
The severity of RHSA-2026:52391 is classified as high, with a score of 7.
How do I fix RHSA-2026:52391?
To fix RHSA-2026:52391, you should apply the latest security update for osbuild-composer as provided by Red Hat.
What does RHSA-2026:52391 address?
RHSA-2026:52391 addresses a security vulnerability in osbuild-composer, which could potentially impact the building of OS artifacts.
What systems are affected by RHSA-2026:52391?
RHSA-2026:52391 affects Red Hat Enterprise Linux for x86_64, including various versions and packages of osbuild-composer.
Is there a risk associated with not updating for RHSA-2026:52391?
Yes, not updating for RHSA-2026:52391 could leave your systems vulnerable to security exploits related to the osbuild-composer service.