Bug 2481767 (CVE-2026-48962)
| Summary: | CVE-2026-48962 perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in perl-IO-Compress, a component used for data compression and decompression. A remote attacker could exploit this vulnerability by crafting a malicious input, specifically an output glob, that bypasses the intended security measures. This could lead to the execution of unauthorized code on the system, potentially allowing the attacker to take full control of the affected process.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2483254 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-05-27 04:01:23 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:29210 https://access.redhat.com/errata/RHSA-2026:29210 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:29182 https://access.redhat.com/errata/RHSA-2026:29182 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:29867 https://access.redhat.com/errata/RHSA-2026:29867 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:29941 https://access.redhat.com/errata/RHSA-2026:29941 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:30086 https://access.redhat.com/errata/RHSA-2026:30086 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:30115 https://access.redhat.com/errata/RHSA-2026:30115 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:30085 https://access.redhat.com/errata/RHSA-2026:30085 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:30843 https://access.redhat.com/errata/RHSA-2026:30843 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:30858 https://access.redhat.com/errata/RHSA-2026:30858 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:30851 https://access.redhat.com/errata/RHSA-2026:30851 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:30859 https://access.redhat.com/errata/RHSA-2026:30859 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:30860 https://access.redhat.com/errata/RHSA-2026:30860 |