RHSA-2026:7383: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/cockpitto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-bridgeto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-debuginfoto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-debugsourceto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-docto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-packagekitto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-storagedto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-systemto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-wsto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpit-ws-selinuxto a version that resolves this vulnerability.Fixed in 344-3.el10_1 - Upgrade
Upgrade
redhat/cockpitto a version that resolves this vulnerability.Fixed in 344-3.el10_1.aa - Upgrade
Upgrade
redhat/cockpit-debuginfoto a version that resolves this vulnerability.Fixed in 344-3.el10_1.aa - Upgrade
Upgrade
redhat/cockpit-debugsourceto a version that resolves this vulnerability.Fixed in 344-3.el10_1.aa - Upgrade
Upgrade
redhat/cockpit-wsto a version that resolves this vulnerability.Fixed in 344-3.el10_1.aa - Upgrade
Upgrade
redhat/cockpit-ws-selinuxto a version that resolves this vulnerability.Fixed in 344-3.el10_1.aa - Upgrade
Upgrade
cockpitto a version that resolves this vulnerability.Patch CVE-2026-4631
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:7383?
The vulnerability RHSA-2026:7383 is classified as critical.
How do I fix RHSA-2026:7383?
To remediate RHSA-2026:7383, you should update the cockpit package to version 344-3.el10_1.
What systems are affected by RHSA-2026:7383?
RHSA-2026:7383 affects Red Hat Enterprise Linux for x86_64, IBM z Systems, ARM 64, and Power, little endian.
What type of vulnerability is RHSA-2026:7383?
RHSA-2026:7383 involves unauthenticated remote code execution due to SSH command-line argument injection.
Is there a workaround for RHSA-2026:7383?
There are no documented workarounds for RHSA-2026:7383, so updating the affected packages is necessary.