ELSA-2025-22011

ELSA-2025-22011 - buildah security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2025-11-25

Description


[1.41.6-1.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]

[2:1.41.6-1]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.41
(https://github.com/containers/buildah/commit/2ece502)
- fixes '[Minor Incident] CVE-2025-52881 buildah: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [rhel-9.7.z]'
- Resolves: RHEL-126925

[2:1.41.4-4]
- rebuild for CVE-2025-58183
- Resolves: RHEL-125680

[2:1.41.4-3]
- fix the TMT tests
- Related: RHEL-115166

[2:1.41.4-2]
- rebuild as last build was built in the wrong tag
- Related: RHEL-115166

[2:1.41.4-1]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.41
(https://github.com/containers/buildah/commit/ee5b574)
- fixes 'buildah: create parent directories of mount targets with mode 0755 - [RHEL-9.7] 0day'
- Resolves: RHEL-115166


Related CVEs


CVE-2025-52881
CVE-2025-58183

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) buildah-1.41.6-1.0.1.el9_7.src.rpm50a0f50424870426fd62f150a9b286722d84508460c2fc297f4920dff89b53b6-ol9_aarch64_appstream
buildah-1.41.6-1.0.1.el9_7.aarch64.rpm55117980afd69ce9c769e7041bab266638a0d511a605ba621027cfea33b148af-ol9_aarch64_appstream
buildah-tests-1.41.6-1.0.1.el9_7.aarch64.rpm1822359877d836fbf3911fcea49be783d778e1aff95a1ce6bc9e5409a5b6d196-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) buildah-1.41.6-1.0.1.el9_7.src.rpm50a0f50424870426fd62f150a9b286722d84508460c2fc297f4920dff89b53b6-ol9_x86_64_appstream
buildah-1.41.6-1.0.1.el9_7.x86_64.rpm63aa341ed39e8b518cdbd01e161ddbb300be2f47877e51ee6ef2077e756b231d-ol9_x86_64_appstream
buildah-tests-1.41.6-1.0.1.el9_7.x86_64.rpmec1d729a3cfb101c0c3b3abfbf5940fc14358d436d6704a2a7d7cdf11e8e2569-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete