Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Oracle Linux 9 ELSA-2025-9147 moderate: buildah request smuggling

oracle
Calendar Grey June 18, 2025
Oracle Linux Logo Esm H88
Recent buildah packages for Oracle Linux 9 resolve a medium-level vulnerability. Urgent action advised.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[1.39.4-2.0.1] - Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178] [2:1.39.4-2] - rebuild to fix CVE-2025-22871 buildah: Request smuggling due to acceptance of invalid chunked data in net/http - Resolves: RHEL-89294

SRPMs

http://oss.oracle.com/ol9/SRPMS-updates//buildah-1.39.4-2.0.1.el9_6.src.rpm

x86_64

buildah-1.39.4-2.0.1.el9_6.x86_64.rpm buildah-tests-1.39.4-2.0.1.el9_6.x86_64.rpm

aarch64

buildah-1.39.4-2.0.1.el9_6.aarch64.rpm buildah-tests-1.39.4-2.0.1.el9_6.aarch64.rpm

Related CVEs: CVE-2025-22871

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here