Описание
Security update for ansible-core
This update for ansible-core fixes the following issues:
- CVE-2026-11332: Argument injection in ansible-galaxy role install leads to arbitrary code execution (bsc#1267822).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
ansible-test-2.18.3-150400.9.14.1
SUSE Linux Enterprise Module for Systems Management 15 SP7
ansible-core-2.18.3-150400.9.14.1
Ссылки
- Link for SUSE-SU-2026:2680-1
- E-Mail link for SUSE-SU-2026:2680-1
- SUSE Security Ratings
- SUSE Bug 1267822
- SUSE CVE CVE-2026-11332 page
Описание
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:ansible-test-2.18.3-150400.9.14.1
SUSE Linux Enterprise Module for Systems Management 15 SP7:ansible-core-2.18.3-150400.9.14.1
Ссылки
- CVE-2026-11332
- SUSE Bug 1267822