[ALSA-2026:0436] Important: buildah security update
Type:
security
Severity:
important
Release date:
2026-01-16
Description:
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 buildah-tests-1.41.8-1.el10_1.aarch64.rpm 767c78f4c4f7cd0789f3069c3da51590ae815e5d8cc44765e2dc8efe625ecf6b
aarch64 buildah-1.41.8-1.el10_1.aarch64.rpm 8d85040c917512a88da4c04214c812fdd76fb1d227ed9e7717e0b67162a12839
ppc64le buildah-tests-1.41.8-1.el10_1.ppc64le.rpm 07019833e9917fab596442978822b8058776aac4970421a4fde6674e5068d9e2
ppc64le buildah-1.41.8-1.el10_1.ppc64le.rpm 14a99449be3cf75edcbd1dbe6d75ee8fb17d922e5b6dea4232baf11e88c47c0d
s390x buildah-1.41.8-1.el10_1.s390x.rpm 7718493e0ab27c4e434e9bddbb0c040dcdd9ea2c87da8d791e5567a5dbf23c57
s390x buildah-tests-1.41.8-1.el10_1.s390x.rpm b246d061d6e3f49788a397368438fe823ebbb6c5fc33814e65ebc68df9ba27c2
x86_64 buildah-tests-1.41.8-1.el10_1.x86_64.rpm 4f2907ee2a236a0b5d561bf0208924bceed0d919f539403257e9314342bd55fe
x86_64 buildah-1.41.8-1.el10_1.x86_64.rpm a51d501b3126eda614a5133e4985fc97e0fbd1e2bb007d79893cb37b393f521d
x86_64_v2 buildah-tests-1.41.8-1.el10_1.x86_64_v2.rpm d23444426636b6751dea7b6abee70e211e0be05bd581a203873598d2b0c5701c
x86_64_v2 buildah-1.41.8-1.el10_1.x86_64_v2.rpm d9b7ad56eec14c7f91b21e19131f6681b79b6e48938eef6ad08a429b184d51cc
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.