[ALSA-2026:19186] Important: buildah security update
Type:
security
Severity:
important
Release date:
2026-05-26
Description:
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 buildah-tests-1.43.1-1.el9_8.aarch64.rpm 4011a632b3ec605801bf9ba0ac3a449e76aeb18a3fdfa30847b587331be50a71
aarch64 buildah-1.43.1-1.el9_8.aarch64.rpm d698ef6d9e756c8091c08af309c7e04daadd8ec7651855bd88c2f5745be6c0e4
ppc64le buildah-tests-1.43.1-1.el9_8.ppc64le.rpm 6549075c797ade43216af7bddaea2f6293070507831f4912ef993b9630be7a81
ppc64le buildah-1.43.1-1.el9_8.ppc64le.rpm d383a2f97b9aa65d66e2e953044db0b536835e60905f0b8c6b6191b36026e0cc
s390x buildah-tests-1.43.1-1.el9_8.s390x.rpm 32f8e719af4a5079ee974b4ff9b8c55702a823f79e726bd3d33da3de863835ad
s390x buildah-1.43.1-1.el9_8.s390x.rpm 4d9d7612bf0de926d70c25f0e2a5bf1f6ed42bde22d857f6eceaa1ba33db8c25
x86_64 buildah-1.43.1-1.el9_8.x86_64.rpm 7f65c6cbc63c16dc90be94312a830839fe9f33ffd7ee102e2ca8535ea94a3f27
x86_64 buildah-tests-1.43.1-1.el9_8.x86_64.rpm 82352622f0057131a1a6b6dd6dce842520fcccb05fb684654a62d3068c11c92c
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.