Описание
ELSA-2026-47178: yelp security update (IMPORTANT)
[2:40.3-3.1]
- Fix CVE-2026-13601 (RHEL-190224)
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
yelp
40.3-3.el9_8.1
yelp-devel
40.3-3.el9_8.1
yelp-libs
40.3-3.el9_8.1
Oracle Linux x86_64
yelp
40.3-3.el9_8.1
yelp-devel
40.3-3.el9_8.1
yelp-libs
40.3-3.el9_8.1
Связанные CVE
Связанные уязвимости
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
A flaw was found in Yelp due to an overly permissive Content Security ...