Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:7384 - Security Advisory
发布:
2026-04-10
已更新:
2026-04-10

RHSA-2026:7384 - Security Advisory

  • 概述
  • 更新的软件包

概述

Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection

类型/严重性

Security Advisory: Critical

Red Hat Lightspeed patch analysis

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for cockpit is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of
Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.

描述

Cockpit enables users to administer GNU/Linux servers using a web browser. It
offers network configuration, log inspection, diagnostic reports, SELinux
troubleshooting, interactive command-line sessions, and more.

Security Fix(es):

  • cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

解决方案

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

修复

(none)

CVE

  • CVE-2026-4631

参考

  • https://access.redhat.com/security/updates/classification/#critical
注:: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux for x86_64 9

SRPM
cockpit-344-2.el9_7.src.rpm SHA-256: 143d15e266c62cfdcea0e15cc1c4ec87352f0ecc09365b6c3b375629081057e9
x86_64
cockpit-344-2.el9_7.x86_64.rpm SHA-256: 49624925618853ba3048c227ab9d942bcdeb18c5671827aad78c015ce330054c
cockpit-bridge-344-2.el9_7.noarch.rpm SHA-256: af62520cc820231085594bcebdadec838a7111d67429a528a582851897132793
cockpit-debuginfo-344-2.el9_7.x86_64.rpm SHA-256: b5eeae4a50dbe2cd04eb0baf1b5895384ca0f82520421aa10e61ef191230b532
cockpit-debugsource-344-2.el9_7.x86_64.rpm SHA-256: 453508203d10106710ea1cc433b2eed32710582305d4d84094d9dbf83182449d
cockpit-doc-344-2.el9_7.noarch.rpm SHA-256: ca733845a8bf5f7300698a7e42a5f461546085acc57c17c3325f8e1e09d09152
cockpit-packagekit-344-2.el9_7.noarch.rpm SHA-256: 71b3e2f1d7bf178f7f62450f63074e5dec057ae8d5a769f77bff6dc3d405df8c
cockpit-storaged-344-2.el9_7.noarch.rpm SHA-256: fa86dd61ef01670f1f4495012e0c7bd2cc517552b077f3763a01bc087d2a52cf
cockpit-system-344-2.el9_7.noarch.rpm SHA-256: 587dcd1b7a90d2dd8eef98371c1a13e2ed75d98405bb6954a5fd774c63317e5c
cockpit-ws-344-2.el9_7.x86_64.rpm SHA-256: 6bb1488837bd8a447aeefda6eba74dfff0026e541f47625a4445b5029d39e15f
cockpit-ws-selinux-344-2.el9_7.x86_64.rpm SHA-256: 8521c87f368023b3d86bf6695932d3729f2bd8a482666f68cf2f9e7bf6655382

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
cockpit-344-2.el9_7.src.rpm SHA-256: 143d15e266c62cfdcea0e15cc1c4ec87352f0ecc09365b6c3b375629081057e9
s390x
cockpit-344-2.el9_7.s390x.rpm SHA-256: d41e830acfdf9b73414cb9a089aff785ce2880e998144948a9094ff7eb1c3fc5
cockpit-bridge-344-2.el9_7.noarch.rpm SHA-256: af62520cc820231085594bcebdadec838a7111d67429a528a582851897132793
cockpit-debuginfo-344-2.el9_7.s390x.rpm SHA-256: bee08b78fe98793b7e96f7cf62c447a2fc1a973920a83254b9ea07b50ceb1304
cockpit-debugsource-344-2.el9_7.s390x.rpm SHA-256: 44af9a8243652d7b147195b7fa18510de4a7118273c143cee5f0167f6f4977a0
cockpit-doc-344-2.el9_7.noarch.rpm SHA-256: ca733845a8bf5f7300698a7e42a5f461546085acc57c17c3325f8e1e09d09152
cockpit-packagekit-344-2.el9_7.noarch.rpm SHA-256: 71b3e2f1d7bf178f7f62450f63074e5dec057ae8d5a769f77bff6dc3d405df8c
cockpit-storaged-344-2.el9_7.noarch.rpm SHA-256: fa86dd61ef01670f1f4495012e0c7bd2cc517552b077f3763a01bc087d2a52cf
cockpit-system-344-2.el9_7.noarch.rpm SHA-256: 587dcd1b7a90d2dd8eef98371c1a13e2ed75d98405bb6954a5fd774c63317e5c
cockpit-ws-344-2.el9_7.s390x.rpm SHA-256: 1ea3dee536152a0210240f2b0baa4cf5c2fe022b88f691b8364d29363263d242
cockpit-ws-selinux-344-2.el9_7.s390x.rpm SHA-256: 724a7a5f703655ca1d14de361f016c13cecab13e962553133186ac5173ba76d6

Red Hat Enterprise Linux for Power, little endian 9

SRPM
cockpit-344-2.el9_7.src.rpm SHA-256: 143d15e266c62cfdcea0e15cc1c4ec87352f0ecc09365b6c3b375629081057e9
ppc64le
cockpit-344-2.el9_7.ppc64le.rpm SHA-256: 58860d162f2bc383a3f35b1d89252411a360189458695b244b99667e4cde7b36
cockpit-bridge-344-2.el9_7.noarch.rpm SHA-256: af62520cc820231085594bcebdadec838a7111d67429a528a582851897132793
cockpit-debuginfo-344-2.el9_7.ppc64le.rpm SHA-256: 8603a2af221b9aab24365020957d1a99cce15dcdeb2c1b527d528e1cd184f778
cockpit-debugsource-344-2.el9_7.ppc64le.rpm SHA-256: e88f9db7fb18782c3dfb7d993e45279e43d1e1a627559903c3e03658b9d463af
cockpit-doc-344-2.el9_7.noarch.rpm SHA-256: ca733845a8bf5f7300698a7e42a5f461546085acc57c17c3325f8e1e09d09152
cockpit-packagekit-344-2.el9_7.noarch.rpm SHA-256: 71b3e2f1d7bf178f7f62450f63074e5dec057ae8d5a769f77bff6dc3d405df8c
cockpit-storaged-344-2.el9_7.noarch.rpm SHA-256: fa86dd61ef01670f1f4495012e0c7bd2cc517552b077f3763a01bc087d2a52cf
cockpit-system-344-2.el9_7.noarch.rpm SHA-256: 587dcd1b7a90d2dd8eef98371c1a13e2ed75d98405bb6954a5fd774c63317e5c
cockpit-ws-344-2.el9_7.ppc64le.rpm SHA-256: 9119f308487cec6fd5a2f344f5fa83ab8178bdcfddc6d864e77eb5e2b243112d
cockpit-ws-selinux-344-2.el9_7.ppc64le.rpm SHA-256: 077b5adab0184e713c37f01c6412d2b3fb8f1674763c95bc5e4a6864f753d5e6

Red Hat Enterprise Linux for ARM 64 9

SRPM
cockpit-344-2.el9_7.src.rpm SHA-256: 143d15e266c62cfdcea0e15cc1c4ec87352f0ecc09365b6c3b375629081057e9
aarch64
cockpit-344-2.el9_7.aarch64.rpm SHA-256: 9a9b6bfca26c2b29cb10965ab377d93221cfa3c3c6ff02603d775786747e43cd
cockpit-bridge-344-2.el9_7.noarch.rpm SHA-256: af62520cc820231085594bcebdadec838a7111d67429a528a582851897132793
cockpit-debuginfo-344-2.el9_7.aarch64.rpm SHA-256: f09fe922f2abf3bfec2bd25df28b32909f5a8026f85a7411d5127d2aaa3cedf6
cockpit-debugsource-344-2.el9_7.aarch64.rpm SHA-256: 7c3dd9f6e08e814fcb6cb77cb8909fbf494466d4a1d9d43ea3bffaf9b6dc6ab0
cockpit-doc-344-2.el9_7.noarch.rpm SHA-256: ca733845a8bf5f7300698a7e42a5f461546085acc57c17c3325f8e1e09d09152
cockpit-packagekit-344-2.el9_7.noarch.rpm SHA-256: 71b3e2f1d7bf178f7f62450f63074e5dec057ae8d5a769f77bff6dc3d405df8c
cockpit-storaged-344-2.el9_7.noarch.rpm SHA-256: fa86dd61ef01670f1f4495012e0c7bd2cc517552b077f3763a01bc087d2a52cf
cockpit-system-344-2.el9_7.noarch.rpm SHA-256: 587dcd1b7a90d2dd8eef98371c1a13e2ed75d98405bb6954a5fd774c63317e5c
cockpit-ws-344-2.el9_7.aarch64.rpm SHA-256: 20e65685f5ad9cfcfbab8916de82541b26c79bcd4aa15ea4fd8fd8d32719031f
cockpit-ws-selinux-344-2.el9_7.aarch64.rpm SHA-256: fb984f11bfa192b00bf09c5fe5247ff1a15def7d8241286eedcc965c41527709

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility