-
Tue Sep 01 2026 Jindrich Novy <jnovy@redhat.com> - 2:1.33.14-6
- rebuild with updated Go to fix CVE-2026-42499
- Resolves: RHEL-241668 RHEL-242027 RHEL-242107 RHEL-242222 RHEL-242343 RHEL-242382 RHEL-251834
-
Thu Aug 20 2026 Jindrich Novy <jnovy@redhat.com> - 2:1.33.14-5
- rebuild with Go 1.25.11 to fix CVE-2026-33818, CVE-2026-56853, CVE-2026-56858,
CVE-2026-56859, CVE-2026-56860, CVE-2026-56862
-
Wed Jul 01 2026 Jindrich Novy <jnovy@redhat.com> - 2:1.33.14-4
- switch source URL from GitHub to the internal GitLab sustaining-engineering repo
- update to the latest content of release-1.33 (commit 2cbee78)
- bump golang.org/x/crypto to v0.53.0 to fix CVE-2026-39829, CVE-2026-39830, CVE-2026-39832
-
Tue Feb 17 2026 Jindrich Novy <jnovy@redhat.com> - 2:1.33.14-3
- rebuild for CVE-2025-68121
- Resolves: RHEL-149262
-
Mon Feb 02 2026 Jindrich Novy <jnovy@redhat.com> - 2:1.33.14-2
- rebuild for CVE-2025-61729
- Resolves: RHEL-140529
-
Fri Jan 09 2026 Jindrich Novy <jnovy@redhat.com> - 2:1.33.14-1
- update to the latest content of https://github.com/containers/buildah/tree/release-1.33
(https://github.com/containers/buildah/commit/a7f8179)
- fixes "CVE-2025-47913 container-tools:rhel8/buildah: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [rhel-8.10.z]"
- Resolves: RHEL-130974
-
Mon Dec 15 2025 Jindrich Novy <jnovy@redhat.com> - 2:1.33.13-1
- update to the latest content of https://github.com/containers/buildah/tree/release-1.33
(https://github.com/containers/buildah/commit/65707d0)
- fixes "[Minor Incident] CVE-2025-52881 container-tools:rhel8/buildah: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [rhel-8.10.z]"
- Resolves: RHEL-126916
-
Wed Dec 03 2025 Jindrich Novy <jnovy@redhat.com> - 2:1.33.12-3
- rebuild for CVE-2025-58183
- Resolves: RHEL-125644
-
Tue May 06 2025 Jindrich Novy <jnovy@redhat.com> - 2:1.33.12-2
- update to the latest content of https://github.com/containers/buildah/tree/release-1.33
(https://github.com/containers/buildah/commit/cf49e7c)
- fixes "CVE-2025-22871 container-tools:rhel8/buildah: Request smuggling due to acceptance of invalid chunked data in net/http [rhel-8.10.z]"
- Resolves: RHEL-89239
-
Fri Jan 24 2025 Jindrich Novy <jnovy@redhat.com> - 2:1.33.12-1
- update to the latest content of https://github.com/containers/buildah/tree/release-1.33
(https://github.com/containers/buildah/commit/58af1cd)
- Resolves: RHEL-67612