Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2680-1

Опубликовано: 29 июн. 2026
Источник: suse-cvrf

Описание

Security update for ansible-core

This update for ansible-core fixes the following issues:

  • CVE-2026-11332: Argument injection in ansible-galaxy role install leads to arbitrary code execution (bsc#1267822).

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP7
ansible-test-2.18.3-150400.9.14.1
SUSE Linux Enterprise Module for Systems Management 15 SP7
ansible-core-2.18.3-150400.9.14.1

Описание

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:ansible-test-2.18.3-150400.9.14.1
SUSE Linux Enterprise Module for Systems Management 15 SP7:ansible-core-2.18.3-150400.9.14.1

Ссылки
Уязвимость SUSE-SU-2026:2680-1