[WID-SEC-2026-2645] Red Hat Enterprise Linux (sg3_utils): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten CVSS Base Score 7.6 (hoch) CVSS Temporal Score 6.6 (mittel) Remoteangriff nein Datum 04.08.2026 Stand 05.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Produktbeschreibung Red Hat Enterprise Linux (RHEL) ist eine populäre Linux-Distribution. Produkte 04.08.2026 Oracle Linux Red Hat Enterprise Linux 9 Red Hat Enterprise Linux 10 Angriff Angriff Ein Angreifer mit physischem Zugriff kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A local attacker with physical access can exploit a vulnerability in the `sg3_utils` package on Red Hat Enterprise Linux to execute arbitrary code with root privileges. The vulnerability has a CVSS base score of 7.6 (High) and affects Red Hat Enterprise Linux 9 and 10, as well as Oracle Linux. A mitigation is available, but the article does not specify a fixed version number or the exact workaround.