Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-21676

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-21676: cockpit security update (IMPORTANT)

[356.2-1.0.1]

  • Storage: Enable btrfs support [Orabug: 37464632]
  • Replaced upstream urls in documentation with oracle links [Orabug: 36528753]
  • Drop subscription-manager-cockpit requirement for ol [Orabug: 34681110]
  • Remove duplicate reference to server in cockpit [Orabug: 34030494]
  • Update documentation links [Orabug: 30271413], [Orabug: 32013095], [Orabug: 32795691], [Orabug: 34398512], [Orabug: 34742876], [Orabug: 37253273]
  • Update spec file for new release

[356.1-1]

  • ws: Prevent remote code execution with SSH argument injection (RHEL-158306)
  • node: update lodash dependency (RHEL-164067)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

cockpit

356.2-1.0.1.el10_2

cockpit-bridge

356.2-1.0.1.el10_2

cockpit-doc

356.2-1.0.1.el10_2

cockpit-packagekit

356.2-1.0.1.el10_2

cockpit-storaged

356.2-1.0.1.el10_2

cockpit-system

356.2-1.0.1.el10_2

cockpit-ws

356.2-1.0.1.el10_2

cockpit-ws-selinux

356.2-1.0.1.el10_2

Oracle Linux x86_64

cockpit

356.2-1.0.1.el10_2

cockpit-bridge

356.2-1.0.1.el10_2

cockpit-doc

356.2-1.0.1.el10_2

cockpit-packagekit

356.2-1.0.1.el10_2

cockpit-storaged

356.2-1.0.1.el10_2

cockpit-system

356.2-1.0.1.el10_2

cockpit-ws

356.2-1.0.1.el10_2

cockpit-ws-selinux

356.2-1.0.1.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 8
ubuntu
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
redhat
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
nvd
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
debian
3 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attack ...

suse-cvrf
около 1 месяца назад

Security update for cockpit