Bug 2461065 (CVE-2026-41988)

Summary: CVE-2026-41988 uuid: uuid: Unexpected data writes when using external output buffers with specific UUID versions
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: aadhikar, aazores, abarbaro, abrianik, abuckta, alcohan, alinfoot, alizardo, amctagga, anjoseph, anpicker, anthomas, aoconnor, asoldano, bbaranow, bbrownin, bdettelb, bmaxwell, bniver, brasmith, bsmejkal, bstansbe, caswilli, cdrage, chfoley, cmah, cmyers, cochase, dbosanac, derez, dhanak, dkuc, dlofthou, dnakabaa, doconnor, dranck, drosa, dschmidt, dsimansk, dtrifiro, dymurray, eaguilar, ebaron, eborisov, ebourniv, ehelms, erezende, eshamard, ewittman, fdeutsch, flucifre, ggainey, ggrzybek, gmalinko, gmeno, gotiwari, gparvin, groman, hasun, ibek, ibolton, istudens, ivassile, iweiss, jachapma, janstey, jbalunas, jcantril, jchui, jfula, jgrulich, jhe, jhorak, jkoehler, jlanda, jmatthew, jmontleo, jolong, jowilson, jprabhak, jraez, jreimann, jrokos, juwatts, jvasik, jwong, kaycoth, kingland, kshier, ktsao, kverlaen, lball, lchilton, lcouzens, lgallett, lphiri, manissin, mbarnett, mbenjamin, mdessi, mhackett, mhulan, mnovotny, mosmerov, mreynolds, mrizzi, mstipich, msvehla, mvyas, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, orabin, oramraz, osousa, pahickey, pantinor, parichar, pberan, pcattana, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, progier, psrna, ptisnovs, rblanco, rbryant, rchan, rexwhite, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rojacob, rstancel, rstepani, rushinde, sausingh, sbunciak, sdawley, sdoran, sfeifer, simaishi, slucidi, smaestri, smallamp, smcdonal, smullick, snegrini, sostapov, spichugi, sseago, stcannon, sthirugn, stirabos, swoodman, syedriko, tasato, tbordaz, teagle, thason, thjenkin, tmalecek, tpopela, ttakamiy, vashirov, vdosoudi, vereddy, veshanka, watson-tool-maintainers, weaton, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in uuid. When external output buffers are used with UUID versions 3, 5, or 6, an attacker with local access may be able to cause unexpected data writes. This vulnerability could lead to low impact data integrity issues. UUID version 4 is not affected.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-04-23 05:01:28 UTC
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.