Red Hat Security Advisory: Red Hat OpenShift Builds 1.7.2
Releases of Red Hat OpenShift Builds 1.7.2
AI Analysis
Technical Summary
The osbuild-composer service in Red Hat Enterprise Linux 9.6 Extended Update Support is affected by two security vulnerabilities. CVE-2025-68121 is a flaw in the crypto/tls package causing incorrect certificate validation during TLS session resumption, potentially allowing unexpected session resumption. CVE-2026-25679 is an issue in the net/url package where IPv6 host literals are parsed incorrectly. These vulnerabilities have been addressed in the updated osbuild-composer packages provided by Red Hat. The advisory references the Red Hat Security Advisory RHSA-2026:19475 for further details and patch information.
Potential Impact
The vulnerabilities impact the security of TLS session resumption and URL parsing within the osbuild-composer service, which could affect the integrity and security of OS artifact building and image uploading processes. Incorrect TLS session resumption validation may expose the service to potential man-in-the-middle or session hijacking risks. Incorrect IPv6 parsing could lead to improper handling of network addresses, potentially causing security or operational issues. Red Hat rates the overall security impact as Important.
Mitigation Recommendations
Red Hat has released updated osbuild-composer packages that address these vulnerabilities. Users of Red Hat Enterprise Linux 9.6 Extended Update Support and related variants should apply the provided security update as detailed in Red Hat Advisory RHSA-2026:19475. The advisory includes instructions on how to obtain and install the fixed packages. No additional mitigation steps are indicated beyond applying the official update.
Red Hat Security Advisory: Red Hat OpenShift Builds 1.7.2
Description
Releases of Red Hat OpenShift Builds 1.7.2
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The osbuild-composer service in Red Hat Enterprise Linux 9.6 Extended Update Support is affected by two security vulnerabilities. CVE-2025-68121 is a flaw in the crypto/tls package causing incorrect certificate validation during TLS session resumption, potentially allowing unexpected session resumption. CVE-2026-25679 is an issue in the net/url package where IPv6 host literals are parsed incorrectly. These vulnerabilities have been addressed in the updated osbuild-composer packages provided by Red Hat. The advisory references the Red Hat Security Advisory RHSA-2026:19475 for further details and patch information.
Potential Impact
The vulnerabilities impact the security of TLS session resumption and URL parsing within the osbuild-composer service, which could affect the integrity and security of OS artifact building and image uploading processes. Incorrect TLS session resumption validation may expose the service to potential man-in-the-middle or session hijacking risks. Incorrect IPv6 parsing could lead to improper handling of network addresses, potentially causing security or operational issues. Red Hat rates the overall security impact as Important.
Mitigation Recommendations
Red Hat has released updated osbuild-composer packages that address these vulnerabilities. Users of Red Hat Enterprise Linux 9.6 Extended Update Support and related variants should apply the provided security update as detailed in Red Hat Advisory RHSA-2026:19475. The advisory includes instructions on how to obtain and install the fixed packages. No additional mitigation steps are indicated beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:19475
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-25679"]
- Cvss Version
- null
Threat ID: 6a16097fe29bf47b5064bc62
Added to database: 05/26/2026, 20:58:39 UTC
Last enriched: 07/30/2026, 10:56:34 UTC
Last updated: 07/31/2026, 21:51:38 UTC
Views: 103
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.