buildah-1.43.1-4.el9_8

エラータID: AXSA:2026-1495:07

Release date: 
Friday, August 7, 2026 - 22:00
Subject: 
buildah-1.43.1-4.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

* os: golang: Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-39822
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. buildah-1.43.1-4.el9_8.src.rpm
    MD5: 9745162f082ea54329c31621762a96ac
    SHA-256: 7cc2d40062ac841a612878dc0d761a11672453321b9cb848ff9ccc12a4ce0486
    Size: 10.65 MB

Asianux Server 9 for x86_64
  1. buildah-1.43.1-4.el9_8.x86_64.rpm
    MD5: fc3d28bdc228fe88d76b140836ed9005
    SHA-256: 17a9de7eff2ea1f9f89c6f475e30ca6359b3e08e610071c66aa674bba5a085d9
    Size: 10.63 MB
  2. buildah-tests-1.43.1-4.el9_8.x86_64.rpm
    MD5: 14041068613d4874f9c688c11de3a937
    SHA-256: 9503021bb8424bf5af11fb4aefbd5bb2a3ee68e645b364c7008be6980052b705
    Size: 30.79 MB