CVE-2024-6126: Red Hat Enterprise Linux 10
Low severity, CVSS 3.2. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 0:323.1-1.el9_5 (fixed in 0:323.1-1.el9_5)
Published 2024-07-03. Last modified 2026-06-17.