OESA-2026-2908

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2908
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2908.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2908
Upstream
  • CVE-2026-4802
Published
2026-07-09T12:50:24Z
Modified
2026-07-09T13:00:10.968776959Z
Summary
cockpit security update
Details

Cockpit makes GNU/Linux discoverable. See Linux server in a web browser and perform system tasks with a mouse. It’s easy to start containers, administer storage, configure networks, and inspect logs with this package.

Security Fix(es):

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.(CVE-2024-2947)

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.(CVE-2026-4802)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / cockpit

Package

Name
cockpit
Purl
pkg:rpm/openEuler/cockpit&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
309-8.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "cockpit-309-8.oe2403sp3.x86_64.rpm",
        "cockpit-debuginfo-309-8.oe2403sp3.x86_64.rpm",
        "cockpit-debugsource-309-8.oe2403sp3.x86_64.rpm",
        "cockpit-devel-309-8.oe2403sp3.x86_64.rpm"
    ],
    "src": [
        "cockpit-309-8.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "cockpit-309-8.oe2403sp3.aarch64.rpm",
        "cockpit-debuginfo-309-8.oe2403sp3.aarch64.rpm",
        "cockpit-debugsource-309-8.oe2403sp3.aarch64.rpm",
        "cockpit-devel-309-8.oe2403sp3.aarch64.rpm"
    ],
    "noarch": [
        "cockpit-help-309-8.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2908.json"