Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:7383 - Security Advisory
Issued:
2026-04-10
Updated:
2026-04-10

RHSA-2026:7383 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection

Type/Severity

Security Advisory: Critical

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for cockpit is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of
Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.

Description

Cockpit enables users to administer GNU/Linux servers using a web browser. It
offers network configuration, log inspection, diagnostic reports, SELinux
troubleshooting, interactive command-line sessions, and more.

Security Fix(es):

  • cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

(none)

CVEs

  • CVE-2026-4631

References

  • https://access.redhat.com/security/updates/classification/#critical
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
cockpit-344-3.el10_1.src.rpm SHA-256: b1a03845997a745be2aa2bcace725e54d2ea2e90aef6e6376dbedd98f4b23764
x86_64
cockpit-344-3.el10_1.x86_64.rpm SHA-256: 3d85f9510e50c9fad7c509f5be79dc4b748ee1245d78d9b029f49860bdaab6f1
cockpit-bridge-344-3.el10_1.noarch.rpm SHA-256: a9223e58f7d681000308812930053be83ad0077a323f2038f1bd55f46a66021b
cockpit-debuginfo-344-3.el10_1.x86_64.rpm SHA-256: 795585990e0382e67fd0a0d01c90094512c9e90fa035be1e7d25831f84b93907
cockpit-debugsource-344-3.el10_1.x86_64.rpm SHA-256: 118685ff2214a34d5e1d642f49dac3fef2f246aa58e1f98e8b7e9e6b23214680
cockpit-doc-344-3.el10_1.noarch.rpm SHA-256: 7df4a4b4923f15ba958269d51c392d501fb08b6025c152c1bab9db74bbdc0feb
cockpit-packagekit-344-3.el10_1.noarch.rpm SHA-256: 0cc7822905b96153fd4b2554bf78d1a90b3c2a2994d00a1d38fa83b669ea45f8
cockpit-storaged-344-3.el10_1.noarch.rpm SHA-256: e7440fe7abb05f1cf75455f5d7d1f0662430ae153184ce0dff77350f3262fb50
cockpit-system-344-3.el10_1.noarch.rpm SHA-256: d68534187a84bdc0854af75dba4ebd928df89bcd8410cd319f0898c2a7ce822f
cockpit-ws-344-3.el10_1.x86_64.rpm SHA-256: b14d01a06f41d9d3217c3aea8b8b0c2bb6b81ffe8bc0f512df759f61e84ee0fd
cockpit-ws-selinux-344-3.el10_1.x86_64.rpm SHA-256: 13c8cbfba5bd9b5040cad4481b0f3f1044663647d46d88c06c51b52c271f93b6

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
cockpit-344-3.el10_1.src.rpm SHA-256: b1a03845997a745be2aa2bcace725e54d2ea2e90aef6e6376dbedd98f4b23764
s390x
cockpit-344-3.el10_1.s390x.rpm SHA-256: 920a2e480d5efa5bc2272077434f8aa8f5d2ba776accedb10a2dfbb096baf35c
cockpit-bridge-344-3.el10_1.noarch.rpm SHA-256: a9223e58f7d681000308812930053be83ad0077a323f2038f1bd55f46a66021b
cockpit-debuginfo-344-3.el10_1.s390x.rpm SHA-256: ca0ce72e27aa1586200e42cb751b70d79826d459d3b65d76411c90a58e94cb55
cockpit-debugsource-344-3.el10_1.s390x.rpm SHA-256: c41483f798a93844873cfe917f2d9215ca4553ddb81896bf9b057ba70d7160aa
cockpit-doc-344-3.el10_1.noarch.rpm SHA-256: 7df4a4b4923f15ba958269d51c392d501fb08b6025c152c1bab9db74bbdc0feb
cockpit-packagekit-344-3.el10_1.noarch.rpm SHA-256: 0cc7822905b96153fd4b2554bf78d1a90b3c2a2994d00a1d38fa83b669ea45f8
cockpit-storaged-344-3.el10_1.noarch.rpm SHA-256: e7440fe7abb05f1cf75455f5d7d1f0662430ae153184ce0dff77350f3262fb50
cockpit-system-344-3.el10_1.noarch.rpm SHA-256: d68534187a84bdc0854af75dba4ebd928df89bcd8410cd319f0898c2a7ce822f
cockpit-ws-344-3.el10_1.s390x.rpm SHA-256: eadbe34a20df24110c24add25f552d1ed7abb07907766975ecd8da732e1e0294
cockpit-ws-selinux-344-3.el10_1.s390x.rpm SHA-256: c51beb112f1e2ab1235b8fa66aa57a3f76b07027ef3f88d9165fea37d0958d03

Red Hat Enterprise Linux for Power, little endian 10

SRPM
cockpit-344-3.el10_1.src.rpm SHA-256: b1a03845997a745be2aa2bcace725e54d2ea2e90aef6e6376dbedd98f4b23764
ppc64le
cockpit-344-3.el10_1.ppc64le.rpm SHA-256: 4f9cda1ebb1c0a0d42d0d1b40ef4fa30ad3b011d05bbb5ebb44f7cf17427f838
cockpit-bridge-344-3.el10_1.noarch.rpm SHA-256: a9223e58f7d681000308812930053be83ad0077a323f2038f1bd55f46a66021b
cockpit-debuginfo-344-3.el10_1.ppc64le.rpm SHA-256: eed3e20bf9a88e1d22aea967e33f5f1495bc054e4afbb159126a663f81fc1732
cockpit-debugsource-344-3.el10_1.ppc64le.rpm SHA-256: db454bbe90791d293362dc2d0449216943855ef6ddde5d4465265d9af6afe05a
cockpit-doc-344-3.el10_1.noarch.rpm SHA-256: 7df4a4b4923f15ba958269d51c392d501fb08b6025c152c1bab9db74bbdc0feb
cockpit-packagekit-344-3.el10_1.noarch.rpm SHA-256: 0cc7822905b96153fd4b2554bf78d1a90b3c2a2994d00a1d38fa83b669ea45f8
cockpit-storaged-344-3.el10_1.noarch.rpm SHA-256: e7440fe7abb05f1cf75455f5d7d1f0662430ae153184ce0dff77350f3262fb50
cockpit-system-344-3.el10_1.noarch.rpm SHA-256: d68534187a84bdc0854af75dba4ebd928df89bcd8410cd319f0898c2a7ce822f
cockpit-ws-344-3.el10_1.ppc64le.rpm SHA-256: 4a7c18eeae14d6aedf43d71ccfc7ba222d94370ae1e2d6b3f8cbcd29ae0abd30
cockpit-ws-selinux-344-3.el10_1.ppc64le.rpm SHA-256: 25fd4924f4e854a14e27ff145939a1cdabbb0582ce4ee0d72fe9f671c9999681

Red Hat Enterprise Linux for ARM 64 10

SRPM
cockpit-344-3.el10_1.src.rpm SHA-256: b1a03845997a745be2aa2bcace725e54d2ea2e90aef6e6376dbedd98f4b23764
aarch64
cockpit-344-3.el10_1.aarch64.rpm SHA-256: 0cd46734f39892c0ee5aed141bc41c2a2b69854f6463547d6a823511f1f3270f
cockpit-bridge-344-3.el10_1.noarch.rpm SHA-256: a9223e58f7d681000308812930053be83ad0077a323f2038f1bd55f46a66021b
cockpit-debuginfo-344-3.el10_1.aarch64.rpm SHA-256: 6c6d67642817f9a2e2c837ea9d70828f9c3a92a0ed0b28882645800286a7e4c0
cockpit-debugsource-344-3.el10_1.aarch64.rpm SHA-256: 2148dce649de36df30e06ae9415e83711489eb8c46ab2592db0237769352e355
cockpit-doc-344-3.el10_1.noarch.rpm SHA-256: 7df4a4b4923f15ba958269d51c392d501fb08b6025c152c1bab9db74bbdc0feb
cockpit-packagekit-344-3.el10_1.noarch.rpm SHA-256: 0cc7822905b96153fd4b2554bf78d1a90b3c2a2994d00a1d38fa83b669ea45f8
cockpit-storaged-344-3.el10_1.noarch.rpm SHA-256: e7440fe7abb05f1cf75455f5d7d1f0662430ae153184ce0dff77350f3262fb50
cockpit-system-344-3.el10_1.noarch.rpm SHA-256: d68534187a84bdc0854af75dba4ebd928df89bcd8410cd319f0898c2a7ce822f
cockpit-ws-344-3.el10_1.aarch64.rpm SHA-256: 1ee8290cbefff100cde4f207675aed426c84a3c292c78c69c4126b15c60b50e6
cockpit-ws-selinux-344-3.el10_1.aarch64.rpm SHA-256: a07e02774af9950f32909f834535d13b1f0e53583e0fe469941db042991a2a51

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility