Vulnerability Description
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-18157
- https://bugzilla.redhat.com/show_bug.cgi?id=2465250
- https://github.com/RedHatInsights/yggdrasil-worker-package-manager/commit/959745
- https://github.com/RedHatInsights/yggdrasil-worker-package-manager/releases/tag/
- https://github.com/RedHatInsights/yggdrasil-worker-package-manager/releases/tag/
FAQ
What is CVE-2026-18157?
CVE-2026-18157 is a vulnerability with a CVSS score of 7.8 (HIGH). A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially cr...
How severe is CVE-2026-18157?
CVE-2026-18157 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18157?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.