Red HatCVE-2026-18157
Red Hat yggdrasil-worker-package-manager: argument injection
High7.8CVE-2026-18157 · Published Jul 31, 2026 · updated Aug 3, 2026
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| yggdrasil-worker-package-manager Product | < 0.1.4 | 0.1.4 |
| >= 0.2.0, < 0.2.4 | 0.2.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-88
- www.cve.org/CVERecord?id=CVE-2026-18157
- nvd.nist.gov/vuln/detail/CVE-2026-18157
- access.redhat.com/security/cve/CVE-2026-18157
- bugzilla.redhat.com/show_bug.cgi?id=2465250
- github.com/RedHatInsights/yggdrasil-worker-package-manager/commit/959745bb5917c17f0316af199aace6c71baa5ad7
- github.com/RedHatInsights/yggdrasil-worker-package-manager/releases/tag/0.1.4
- github.com/RedHatInsights/yggdrasil-worker-package-manager/releases/tag/0.2.4
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 31 | Red Hat Ansible Automation Platform 2: improper certificate validation | High8.2 | No fix yet |
| Jul 31 | Red Hat gnome-remote-desktop as shipped: resource exhaustion | High7.5 | No fix yet |
| Jul 31 | A flaw was found in 389 Directory Server | High7.5 | No fix yet |
| Jul 31 | Red Hat: buffer overflow | High7.5 | No fix yet |
| Jul 31 | Red Hat Advanced Cluster Security 4: insufficient authenticity check | High8.5 | No fix yet |
| Jul 31 | Red Hat SAML protocol implementation of Keycloak: improper input validation | Low3.4 | No fix yet |