Bug 2536026 (CVE-2026-92941)
| Summary: | CVE-2026-92941 vm2: vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | abarbaro, alizardo, dschmidt, ikhan, jchui, jhe, jlanda, kshier, ktsao, nboldt, oaljalju, psrna, rbobbitt, simaishi, stcannon, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in vm2. The sandbox improperly exposes the host Transport Layer Security (TLS) module to untrusted code running within the sandbox environment. An attacker can exploit this issue using allowed built-in utilities to modify the process-wide certificate authorities. This manipulation causes the host application to trust attacker-controlled security certificates, potentially allowing secure network communications to be intercepted or spoofed.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-17 13:56:28 UTC
|