Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-21468

Опубликовано: 23 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-21468: cockpit security update (IMPORTANT)

[356.2-1.0.1]

  • Apply the patch for duplicate reference [Orabug: 39250109]
  • Storage: Enable btrfs support [Orabug: 37464632]
  • Replaced upstream urls in documentation with oracle links [Orabug: 36528753]
  • Drop subscription-manager-cockpit requirement for ol [Orabug: 34681110]
  • Remove duplicate reference to server in cockpit [Orabug: 34030494]
  • Update documentation links [Orabug: 30271413], [Orabug: 32013095], [Orabug: 32795691], [Orabug: 34398512], [Orabug: 34742876], [Orabug: 37253273]
  • Update spec file for new release

[356.2]

  • Remove recommends on subscription-manager-cockpit if applicable

[356.1-1]

  • ws: Prevent remote code execution with SSH argument injection (RHEL-158310)
  • node: update lodash dependency (RHEL-164196)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

cockpit

356.2-1.0.1.el9_8

cockpit-bridge

356.2-1.0.1.el9_8

cockpit-doc

356.2-1.0.1.el9_8

cockpit-packagekit

356.2-1.0.1.el9_8

cockpit-storaged

356.2-1.0.1.el9_8

cockpit-system

356.2-1.0.1.el9_8

cockpit-ws

356.2-1.0.1.el9_8

cockpit-ws-selinux

356.2-1.0.1.el9_8

Oracle Linux x86_64

cockpit

356.2-1.0.1.el9_8

cockpit-bridge

356.2-1.0.1.el9_8

cockpit-doc

356.2-1.0.1.el9_8

cockpit-packagekit

356.2-1.0.1.el9_8

cockpit-storaged

356.2-1.0.1.el9_8

cockpit-system

356.2-1.0.1.el9_8

cockpit-ws

356.2-1.0.1.el9_8

cockpit-ws-selinux

356.2-1.0.1.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 8
ubuntu
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
redhat
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
nvd
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
debian
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attack ...

suse-cvrf
около 1 месяца назад

Security update for cockpit