[ALSA-2025:9148] Moderate: buildah security update
Type:
security
Severity:
moderate
Release date:
2025-06-17
Description:
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * net/[http:](http:) Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 buildah-tests-1.39.4-2.el10_0.aarch64.rpm 3a5c4cd38c6e2908bd4ea9631f3f90e755346776578ae3977afae2892ad50879
aarch64 buildah-1.39.4-2.el10_0.aarch64.rpm ff46e7e31a7670a1d76c9e632a2c5eb08a7ed0c3fe8311d36bb137d7072dc1e0
ppc64le buildah-1.39.4-2.el10_0.ppc64le.rpm 25dc39697517c182db1b89d4160ca94e789aac5957614f112c23b71351271075
ppc64le buildah-tests-1.39.4-2.el10_0.ppc64le.rpm 5ba8bd587a08b584630668234bcf8a6d44bea859df8e565bb85135a5c1a74882
s390x buildah-1.39.4-2.el10_0.s390x.rpm 6210b6b64c606e2423864399a21e9fb5340df5ff3451d546a054e3c2cae2e696
s390x buildah-tests-1.39.4-2.el10_0.s390x.rpm ac00327776755a476c607a524ec09411fe41d81f7540d23452578ee0323040de
x86_64 buildah-1.39.4-2.el10_0.x86_64.rpm abbfd5bb6f5eafa6a1cef32496455956e936a3c63d9ac054a20f4cd996dda450
x86_64 buildah-tests-1.39.4-2.el10_0.x86_64.rpm f36b6bfebaa09a448ae85acfef2b3f629753ab271c9c00a25e1326fb3befbbdb
x86_64_v2 buildah-tests-1.39.4-2.el10_0.x86_64_v2.rpm 1f8197ac52ff6cef88d493d0b83f7401d48ed412f5f54d21d86354c8484ec17d
x86_64_v2 buildah-1.39.4-2.el10_0.x86_64_v2.rpm 26d5354fd20ad4094fb0421e65c8ce7ef76f0019819c7560523d7785664f6a79
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.