Bug 2502819 - CVE-2026-16211 ags: Ralph: Race condition leads to incorrect hostname allocation [fedora-all]
Summary: CVE-2026-16211 ags: Ralph: Race condition leads to incorrect hostname allocat...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: ags
Version: rawhide
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Dominik 'Rathann' Mierzejewski
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["706a4bac-2da1-41e6-9122-a...
Depends On:
Blocks: CVE-2026-16211
TreeView+ depends on / blocked
 
Reported: 2026-07-20 14:23 UTC by Ganesh
Modified: 2026-07-20 15:28 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-07-20 15:28:51 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-07-20 14:23:54 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. Executing a manipulation of the argument counter can lead to race condition. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Comment 1 Dominik 'Rathann' Mierzejewski 2026-07-20 15:28:51 UTC
The bundled allegro is not related to ralph at all and the "Allegro" mentioned above is a company name, not project name. See bug 2502821.


Note You need to log in before you can comment on or make changes to this bug.