Fedora Account System
Red Hat Associate
Red Hat Customer
A local sandbox escape and host information disclosure flaw was found in Yelp. A regression introduced in the companion yelp-xsl stylesheet component targets the gnome-42 and master development branches, leaving the application's Content Security Policy (CSP) style handling directives overly permissive. A malicious or compromised sandboxed Flatpak application can programmatically abuse the standard host org.freedesktop.portal.OpenURI portal interface to pass crafted help layout files (ghelp:// or mallard extensions). Because the system portal processes this request silently without requiring user interaction, host-level Yelp is automatically invoked to parse the file outside the application container. The attacker-controlled layout leverages local XML inclusions to load arbitrary host-level files into memory, which are subsequently exfiltrated out-of-band to a remote server using a background CSS url() query embedded inside a structured SVG document.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:47177 https://access.redhat.com/errata/RHSA-2026:47177
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:47178 https://access.redhat.com/errata/RHSA-2026:47178
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:54540 https://access.redhat.com/errata/RHSA-2026:54540
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:54539 https://access.redhat.com/errata/RHSA-2026:54539
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:54605 https://access.redhat.com/errata/RHSA-2026:54605
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:54624 https://access.redhat.com/errata/RHSA-2026:54624
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:54637 https://access.redhat.com/errata/RHSA-2026:54637
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:54666 https://access.redhat.com/errata/RHSA-2026:54666