ELSA-2025-9147

ELSA-2025-9147 - buildah security update

Type:SECURITY
Impact:MODERATE
Release Date:2025-06-17

Description


[1.39.4-2.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]

[2:1.39.4-2]
- rebuild to fix CVE-2025-22871 buildah: Request smuggling due to acceptance of invalid chunked data in net/http
- Resolves: RHEL-89294


Related CVEs


CVE-2025-22871

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) buildah-1.39.4-2.0.1.el9_6.src.rpmfe090cc645bb48e11e178cfeb10650886ad420378a04a51efc9ccd221e45a635-ol9_aarch64_appstream
buildah-1.39.4-2.0.1.el9_6.aarch64.rpmf08ddeb9408cf8005f4c8df35c2644f44bfffefb6ee6435ce42755c762244370-ol9_aarch64_appstream
buildah-tests-1.39.4-2.0.1.el9_6.aarch64.rpm782d74f046fcf07176ead2571863c621f231eb1ef7598df3efdf6fc3e9bb78c1-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) buildah-1.39.4-2.0.1.el9_6.src.rpmfe090cc645bb48e11e178cfeb10650886ad420378a04a51efc9ccd221e45a635-ol9_x86_64_appstream
buildah-1.39.4-2.0.1.el9_6.x86_64.rpm40f8e16168ccb480c6caec5c60ba8707c4b3602163fd7fbfe55f0b3bdfc28647-ol9_x86_64_appstream
buildah-tests-1.39.4-2.0.1.el9_6.x86_64.rpm92417aed3e7349fdab96bd377af5b77839168905bfc2442baf4aa7b790c10ed9-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete