ALSA-2026:18868

See a problem?
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:18868.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2026:18868
Related
Published
2026-05-19T00:00:00Z
Modified
2026-05-26T16:14:21.286159161Z
Summary
Important: linux-sgx security update
Details

The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.

Security Fix(es):

  • qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)
  • node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)
  • node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)
  • lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  • node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinuxRelease Notes linked from the References section.

References

Affected packages

AlmaLinux:9
sgx-common

Package

Name
sgx-common
Purl
pkg:rpm/almalinux/sgx-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el9

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:18868.json"
sgx-libs

Package

Name
sgx-libs
Purl
pkg:rpm/almalinux/sgx-libs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el9

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:18868.json"
sgx-mpa

Package

Name
sgx-mpa
Purl
pkg:rpm/almalinux/sgx-mpa

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el9

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:18868.json"
sgx-pccs

Package

Name
sgx-pccs
Purl
pkg:rpm/almalinux/sgx-pccs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el9

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:18868.json"
sgx-pccs-admin

Package

Name
sgx-pccs-admin
Purl
pkg:rpm/almalinux/sgx-pccs-admin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el9

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:18868.json"
sgx-pckid-tool

Package

Name
sgx-pckid-tool
Purl
pkg:rpm/almalinux/sgx-pckid-tool

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el9

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:18868.json"
tdx-qgs

Package

Name
tdx-qgs
Purl
pkg:rpm/almalinux/tdx-qgs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el9

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:18868.json"