Описание
ELSA-2026-21700: cockpit security update (IMPORTANT)
[310.8-1.0.1]
- Fixed cockpit_ws_t selinux issue for tmpfs [Orabug: 36013589]
- Move update-motd out of cockpit_ws_t context [Orabug: 36013589]
- Update documentation links [Orabug: 34706402]
- Drop subscription-manager-cockpit requirement for ol [Orabug: 34681110]
- Remove duplicate reference to server in cockpit [Orabug: 33862832]
- Update documentation links [Orabug: 32795691]
- Make documentation links point to Oracle Linux information [Orabug: 30271413] [Orabug: 32013095]
- Fix rendering of hwinfo page on systems with some empty memory slots [Orabug: 32826970]
[310.8]
- Remove recommends on subscription-manager-cockpit if applicable
[310.8-1]
- ws: fix uninitialized read in tls-sniffing code
- ws: tighten up branding path construction
- pkg/systemd: robustify argument quoting [CVE-2026-4802] (RHEL-161386)
[310.7-1]
- shell: Determine session idle time and countdown from clock time (RHEL-171011)
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
cockpit
310.8-1.0.1.el8_10
cockpit-bridge
310.8-1.0.1.el8_10
cockpit-doc
310.8-1.0.1.el8_10
cockpit-system
310.8-1.0.1.el8_10
cockpit-ws
310.8-1.0.1.el8_10
Oracle Linux x86_64
cockpit
310.8-1.0.1.el8_10
cockpit-bridge
310.8-1.0.1.el8_10
cockpit-doc
310.8-1.0.1.el8_10
cockpit-system
310.8-1.0.1.el8_10
cockpit-ws
310.8-1.0.1.el8_10
Связанные CVE
Связанные уязвимости
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attack ...