Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21097-1

Опубликовано: 19 июн. 2026
Источник: suse-cvrf

Описание

Security update for ansible-core

This update for ansible-core fixes the following issue

  • CVE-2026-11332: argument injection in ansible-galaxy role install leads to arbitrary code execution (bsc#1267822).

Список пакетов

openSUSE Leap 16.0
ansible-core-2.18.3-160000.3.1
ansible-test-2.18.3-160000.3.1

Описание

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.


Затронутые продукты
openSUSE Leap 16.0:ansible-core-2.18.3-160000.3.1
openSUSE Leap 16.0:ansible-test-2.18.3-160000.3.1

Ссылки