RHSA-2026:62144: Moderate: wget security, bug fix, and enhancement update
Moderate: wget security, bug fix, and enhancement update
Other sources
The wget packages provide the GNU Wget file retrieval utility for HTTP, HTTPS, and FTP protocols.Security Fix(es): wget: GNU Wget: Memory corruption via crafted Metalink URL (CVE-2026-58469) wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption (CVE-2026-58471) wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute (CVE-2026-58472) Bug Fix(es) and Enhancement(s): wget async unsafe code in signal handler context [rhel-8.10.z] (JIRA:RHEL-145875) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/wgetto a version that resolves this vulnerability.Fixed in 1.19.5-16.el8_10 - Upgrade
Upgrade
wgetto a version that resolves this vulnerability.Fixed in rhel-8.10.zPatch JIRA:RHEL-145875 - Compensating control
Apply the security update for the affected wget packages to address the listed CVEs (CVE-2026-58472, CVE-2026-58471, CVE-2026-58469) as described in the advisory referenced for applying the update.
Event History
Frequently Asked Questions
What attacker-controlled content is involved in these vulnerabilities?
The issues involve a crafted Metalink URL, a server-supplied filename, and a crafted HTML attribute. Processing this content with GNU Wget can cause memory corruption or a heap buffer overflow.
What could exploitation allow?
The crafted HTML attribute issue can result in arbitrary code execution or denial of service. The Metalink URL and server-supplied filename issues cause memory corruption.
Which Red Hat Enterprise Linux platforms are covered by this update?
The advisory covers Red Hat Enterprise Linux for x86_64, ARM 64, IBM z Systems, and Power little endian, including the listed Extended Life Cycle variants.
Are there non-security changes included in the update?
Yes. The update also fixes unsafe asynchronous code used in a signal-handler context for rhel-8.10.z.