3.6

CVE-2026-91142

Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds

A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 7
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Dev Spaces
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Dev Spaces
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Dev Spaces
Default Statusunknown
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.006
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 3.6 1 2.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://access.redhat.com/security/cve/CVE-2026-91142
https://bugzilla.redhat.com/show_bug.cgi?id=2479459