CVE-2026-11837: Red Hat Enterprise Linux 10
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:0.2.3-6.el10_0.2 (fixed in 0:0.2.3-6.el10_0.2)
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Openstack Platform 17.1
- Red Hat Red Hat Openstack Platform 18.0
Published 2026-06-10. Last modified 2026-10-08.