RHSA-2025:7118HighCVSS 7.5

Red Hat Security Advisory: osbuild and osbuild-composer security update

Published
May 13, 2025
Last Modified
June 3, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-1394 — golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads CVE-2024-9355 — golang-fips: Golang FIPS zeroed buffer CVE-2024-34158 — go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

🔗 References (13)