CVE-2026-11837: Red Hat Enterprise Linux 10

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:0.2.3-6.el10_0.2 (fixed in 0:0.2.3-6.el10_0.2)
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Openstack Platform 17.1
  • Red Hat Red Hat Openstack Platform 18.0

Published 2026-06-10. Last modified 2026-10-08.