CVE-2018-14650: Red Hat Enterprise Linux Desktop

Medium severity, CVSS 5.0. EPSS: 0.4% chance of exploitation in the next 30 days.

It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.

Affected products

  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Sos-Collector Project Sos-Collector: version 1.4 only

Published 2018-09-27. Last modified 2026-06-17.