RHSA-2026:62143: Moderate: wget security, bug fix, and enhancement update
Moderate: wget security, bug fix, and enhancement update
Other sources
The wget packages provide the GNU Wget file retrieval utility for HTTP, HTTPS, and FTP protocols.Security Fix(es): wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption (CVE-2026-58471) wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute (CVE-2026-58472) Bug Fix(es) and Enhancement(s): wget async unsafe code in signal handler context [rhel-9.8.z] (JIRA:RHEL-220497) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/wgetto a version that resolves this vulnerability.Fixed in 1.21.1-11.el9_8 - Upgrade
Upgrade
redhat/wget-debuginfoto a version that resolves this vulnerability.Fixed in 1.21.1-11.el9_8 - Upgrade
Upgrade
redhat/wget-debugsourceto a version that resolves this vulnerability.Fixed in 1.21.1-11.el9_8 - Upgrade
Upgrade
redhat/wgetto a version that resolves this vulnerability.Fixed in 1.21.1-11.el9_8.aa - Upgrade
Upgrade
redhat/wget-debuginfoto a version that resolves this vulnerability.Fixed in 1.21.1-11.el9_8.aa - Upgrade
Upgrade
redhat/wget-debugsourceto a version that resolves this vulnerability.Fixed in 1.21.1-11.el9_8.aa - Upgrade
Upgrade
wgetto a version that resolves this vulnerability.Fixed in rhel-9.8.zPatch JIRA:RHEL-220497
Event History
Frequently Asked Questions
What attacker-controlled content can trigger these issues?
One issue is triggered by a server-supplied filename and can cause heap memory corruption. Another can be triggered through a crafted HTML attribute and may allow arbitrary code execution or denial of service.
Which deployments should be reviewed for this update?
Review systems using the redhat/wget package on Red Hat Enterprise Linux for ARM 64, including the listed 4-year updates and Extended Life Cycle offerings. The advisory also lists the corresponding debuginfo and debugsource packages.