CVE-2026-18157: Red Hat Enterprise Linux 10
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Redhatinsights Yggdrasil-Worker-Package-Manager: before 0.1.4 (fixed in 0.1.4); from 0.2.0, before 0.2.4 (fixed in 0.2.4)
Published 2026-07-31. Last modified 2026-08-03.