Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42: Important Information Leak in docker-buildx v0.27.0 Resolved

fedora
Calendar Grey August 31, 2025
Dist Fedora Esm H88
Fedora 42 upgrades docker-buildx to version 0.27.0, tackling significant security vulnerabilities and improving capabilities.
Update to release v0.27.0 Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 Upstream new features and fixes

Summary

Docker CLI plugin for extended build capabilities with BuildKit.

Update Information:

Update to release v0.27.0 Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 Upstream new features and fixes

Change Log

* Wed Aug 20 2025 Bradley G Smith - 0.27.0-1 - Update to release v0.27.0 - Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 - Upstream new features and fixes * Sun Aug 17 2025 Bradley G Smith - 0.26.1-6 - Remove temporary fix for go 1.25 rc2 * Fri Aug 15 2025 Maxwell G - 0.26.1-5 - Rebuild for golang-1.25.0 * Fri Aug 15 2025 Maxwell G - 0.26.1-4 - Revert "Rebuild for golang-1.25.0" * Fri Aug 15 2025 Maxwell G - 0.26.1-3 - Rebuild for golang-1.25.0

References


[ 1 ] Bug #2384137 - docker-buildx: go-viper information leak [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2384137 [ 2 ] Bug #2384154 - docker-buildx: go-viper information leak [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2384154 [ 3 ] Bug #2388453 - docker-buildx-0.27.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2388453

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-aeb4a7b52f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: docker-buildx
Product: Fedora 42
Version: 0.27.0
Release: 1.fc42
Summary: Docker CLI plugin for extended build capabilities with BuildKit

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here