attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected products
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 6
Classified as
CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected Products, Subsystems & Sectors
Vendor
Product
Affected Versions
Patch Status
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat Enterprise Linux 7
Red Hat
Red Hat Enterprise Linux 6
Subsystems
OT Supporting Infrastructure
Sectors
Multiple
What to Know
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.