在 中发现了一个缺陷。这一命令注入漏洞允许本地攻击者执行任意命令。该漏洞发生在 处理一个经过特殊构造的归档文件时,其文件名中包含 Shell 元字符,而这些字符在传入 Shell 命令字符串前未被正确转义。成功利用该漏洞需要用户交互,即用户或自动化工作流对恶意文件调用 ,从而对调用用户可访问数据的机密性、完整性和可用性造成严重影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78408 | 7.9 HIGH | Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-84837 | 7.8 HIGH | Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path |
| CVE-2026-78410 | 7.8 HIGH | Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.own |
| CVE-2026-78409 | 7.0 HIGH | Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediat |
| CVE-2026-82968 | 6.4 MEDIUM | Keycloak-services: keycloak-services: cross-session email verification proof not bound to |
| CVE-2026-53683 | 4.3 MEDIUM | Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html |
No comments yet