{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"buildah security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for buildah is now available for openEuler-24.03-LTS-SP2",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"The  package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container&apos;s root file system for manipulation * save container&apos;s root file system layer to create a new image * delete a working container or an image\n\nSecurity Fix(es):\n\nGo JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, \".\") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters.  An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.(CVE-2025-27144)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for buildah is now available for openEuler-24.03-LTS-SP2.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"buildah",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2025-2177",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-2177"
			},
			{
				"summary":"CVE-2025-27144",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-27144&packageName=buildah"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27144"
			},
			{
				"summary":"openEuler-SA-2025-2177 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2025/csaf-openeuler-sa-2025-2177.json"
			}
		],
		"title":"An update for buildah is now available for openEuler-24.03-LTS-SP2",
		"tracking":{
			"initial_release_date":"2025-09-05T20:44:52+08:00",
			"revision_history":[
				{
					"date":"2025-09-05T20:44:52+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2025-09-05T20:44:52+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2025-09-05T20:44:52+08:00",
			"id":"openEuler-SA-2025-2177",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"openEuler-24.03-LTS-SP2",
									"name":"openEuler-24.03-LTS-SP2"
								},
								"name":"openEuler-24.03-LTS-SP2",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-1.34.1-7.oe2403sp2.aarch64.rpm",
									"name":"buildah-1.34.1-7.oe2403sp2.aarch64.rpm"
								},
								"name":"buildah-1.34.1-7.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64.rpm",
									"name":"buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64.rpm"
								},
								"name":"buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-debugsource-1.34.1-7.oe2403sp2.aarch64.rpm",
									"name":"buildah-debugsource-1.34.1-7.oe2403sp2.aarch64.rpm"
								},
								"name":"buildah-debugsource-1.34.1-7.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-tests-1.34.1-7.oe2403sp2.aarch64.rpm",
									"name":"buildah-tests-1.34.1-7.oe2403sp2.aarch64.rpm"
								},
								"name":"buildah-tests-1.34.1-7.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-1.34.1-7.oe2403sp2.src.rpm",
									"name":"buildah-1.34.1-7.oe2403sp2.src.rpm"
								},
								"name":"buildah-1.34.1-7.oe2403sp2.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-1.34.1-7.oe2403sp2.x86_64.rpm",
									"name":"buildah-1.34.1-7.oe2403sp2.x86_64.rpm"
								},
								"name":"buildah-1.34.1-7.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64.rpm",
									"name":"buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64.rpm"
								},
								"name":"buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-debugsource-1.34.1-7.oe2403sp2.x86_64.rpm",
									"name":"buildah-debugsource-1.34.1-7.oe2403sp2.x86_64.rpm"
								},
								"name":"buildah-debugsource-1.34.1-7.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"buildah-tests-1.34.1-7.oe2403sp2.x86_64.rpm",
									"name":"buildah-tests-1.34.1-7.oe2403sp2.x86_64.rpm"
								},
								"name":"buildah-tests-1.34.1-7.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-1.34.1-7.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.aarch64",
					"name":"buildah-1.34.1-7.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64",
					"name":"buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-debugsource-1.34.1-7.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-debugsource-1.34.1-7.oe2403sp2.aarch64",
					"name":"buildah-debugsource-1.34.1-7.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-tests-1.34.1-7.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-tests-1.34.1-7.oe2403sp2.aarch64",
					"name":"buildah-tests-1.34.1-7.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-1.34.1-7.oe2403sp2.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.src",
					"name":"buildah-1.34.1-7.oe2403sp2.src as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-1.34.1-7.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.x86_64",
					"name":"buildah-1.34.1-7.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64",
					"name":"buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-debugsource-1.34.1-7.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-debugsource-1.34.1-7.oe2403sp2.x86_64",
					"name":"buildah-debugsource-1.34.1-7.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"buildah-tests-1.34.1-7.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:buildah-tests-1.34.1-7.oe2403sp2.x86_64",
					"name":"buildah-tests-1.34.1-7.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2025-27144",
			"notes":[
				{
					"text":"Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, \".\") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters.  An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.aarch64",
					"openEuler-24.03-LTS-SP2:buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64",
					"openEuler-24.03-LTS-SP2:buildah-debugsource-1.34.1-7.oe2403sp2.aarch64",
					"openEuler-24.03-LTS-SP2:buildah-tests-1.34.1-7.oe2403sp2.aarch64",
					"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.src",
					"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.x86_64",
					"openEuler-24.03-LTS-SP2:buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64",
					"openEuler-24.03-LTS-SP2:buildah-debugsource-1.34.1-7.oe2403sp2.x86_64",
					"openEuler-24.03-LTS-SP2:buildah-tests-1.34.1-7.oe2403sp2.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.aarch64",
						"openEuler-24.03-LTS-SP2:buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64",
						"openEuler-24.03-LTS-SP2:buildah-debugsource-1.34.1-7.oe2403sp2.aarch64",
						"openEuler-24.03-LTS-SP2:buildah-tests-1.34.1-7.oe2403sp2.aarch64",
						"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.src",
						"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.x86_64",
						"openEuler-24.03-LTS-SP2:buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64",
						"openEuler-24.03-LTS-SP2:buildah-debugsource-1.34.1-7.oe2403sp2.x86_64",
						"openEuler-24.03-LTS-SP2:buildah-tests-1.34.1-7.oe2403sp2.x86_64"
					],
					"details":"buildah security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-2177"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.aarch64",
						"openEuler-24.03-LTS-SP2:buildah-debuginfo-1.34.1-7.oe2403sp2.aarch64",
						"openEuler-24.03-LTS-SP2:buildah-debugsource-1.34.1-7.oe2403sp2.aarch64",
						"openEuler-24.03-LTS-SP2:buildah-tests-1.34.1-7.oe2403sp2.aarch64",
						"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.src",
						"openEuler-24.03-LTS-SP2:buildah-1.34.1-7.oe2403sp2.x86_64",
						"openEuler-24.03-LTS-SP2:buildah-debuginfo-1.34.1-7.oe2403sp2.x86_64",
						"openEuler-24.03-LTS-SP2:buildah-debugsource-1.34.1-7.oe2403sp2.x86_64",
						"openEuler-24.03-LTS-SP2:buildah-tests-1.34.1-7.oe2403sp2.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2025-27144"
		}
	]
}