[ALSA-2025:7147] Moderate: rpm-ostree security update
Type:
security
Severity:
moderate
Release date:
2025-07-02
Description:
The rpm-ostree tool binds together the RPM packaging model with the OSTree model of bootable file system trees. It provides commands that can be used both on client systems and on server-side composes. The rpm-ostree-client package provides commands for client systems to perform upgrades and rollbacks. Security Fix(es): * rust-openssl: rust openssl ssl::select_next_proto use after free (CVE-2025-24898) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinuxRelease Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 rpm-ostree-2025.5-1.el9.aarch64.rpm 04c966fb801484d82c099560ef09d7de46076d5fc4370586aa4779191036390b
aarch64 rpm-ostree-libs-2025.5-1.el9.aarch64.rpm 16c8f514aec0d59e7ff41c8da9409474b3e05de6fa8b95ab02cf07b4bc4b89e2
i686 rpm-ostree-libs-2025.5-1.el9.i686.rpm 07484417f4bf477432ea7d2fa4e0cd3ce5d77996482019492c3b7313e1e9c21b
ppc64le rpm-ostree-libs-2025.5-1.el9.ppc64le.rpm 3fecdd46d5a4710a85b45cb01bdc8eed7eda59b326fadafbce62e49d484cd848
ppc64le rpm-ostree-2025.5-1.el9.ppc64le.rpm 9d9117e2db426694b32704a901595e9e3a03e553e9b60d4afed9cb058d061a3d
s390x rpm-ostree-libs-2025.5-1.el9.s390x.rpm 8530fc55466f88b63c1857b89f7223ecd7a33375624a50a26944be755b8fca14
s390x rpm-ostree-2025.5-1.el9.s390x.rpm a416fbf9992fe72c382a04adb5265f6031a54f456e01f8c396ac2b9b0cdc4005
x86_64 rpm-ostree-2025.5-1.el9.x86_64.rpm 3547785760bc114045d8ceec153b0777b3f945b0785f44bdffefe7e410ff134d
x86_64 rpm-ostree-libs-2025.5-1.el9.x86_64.rpm 5735a5bc44ec2f8affecfc398ace756566613feac01bdb782f28dee2cdc268d0
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.