Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
buildah is not affected by CVE-2026-39832.
The vulnerability affects golang.org/x/crypto/ssh/agent and was fixed in v0.52.0.
The builds shipped in Fedora vendor golang.org/x/crypto v0.53.0, which includes the fix.
Closing as CURRENTRELEASE.