在 软件包中发现了一个缺陷。攻击者可以通过影响 处理的 tarball 的路径或文件名,使其包含 shell 元字符,从而利用命令注入漏洞。这在自动化构建或持续集成(CI)工作流中处理外部提供的构件名称时尤为相关。成功利用该漏洞允许以构建用户的权限执行任意命令,可能导致信息泄露或构建环境的干扰。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78408 | 7.9 HIGH | Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-84838 | 7.8 HIGH | Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() |
| CVE-2026-78410 | 7.8 HIGH | Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.own |
| CVE-2026-78409 | 7.0 HIGH | Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediat |
| CVE-2026-82968 | 6.4 MEDIUM | Keycloak-services: keycloak-services: cross-session email verification proof not bound to |
| CVE-2026-53683 | 4.3 MEDIUM | Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html |
No comments yet