Описание
Security update for ansible-core
This update for ansible-core fixes the following issue
- CVE-2026-11332: argument injection in ansible-galaxy role install leads to arbitrary code execution (bsc#1267822).
Список пакетов
openSUSE Leap 16.0
ansible-core-2.18.3-160000.3.1
ansible-test-2.18.3-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1267822
- SUSE CVE CVE-2026-11332 page
Описание
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
Затронутые продукты
openSUSE Leap 16.0:ansible-core-2.18.3-160000.3.1
openSUSE Leap 16.0:ansible-test-2.18.3-160000.3.1
Ссылки
- CVE-2026-11332
- SUSE Bug 1267822