Back to CVE List

CVE-2026-18157

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-88
Source
NVD
Vendor
RedHatInsights, Red Hat
Product
yggdrasil-worker-package-manager, Red Hat Enterprise Linux 10

External References

Discussion (0)

Add Comment

No comments yet. Be the first!