ansible-core-2.14.18-3.el9_8.1.ML.1

エラータID: AXSA:2026-1731:02

Release date: 
Wednesday, September 2, 2026 - 14:38
Subject: 
ansible-core-2.14.18-3.el9_8.1.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.

Security Fix(es):

* ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-11332
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ansible-core-2.14.18-3.el9_8.1.ML.1.src.rpm
    MD5: 148f879ca389c4e89f076629093e13b1
    SHA-256: 599d8b179bd3274451b7ec79b064c17e79e53aa27f9eea2b09b930a883d3aff3
    Size: 11.26 MB

Asianux Server 9 for x86_64
  1. ansible-core-2.14.18-3.el9_8.1.ML.1.x86_64.rpm
    MD5: 1d3c66ac3e603d9dae788df5a19b6853
    SHA-256: bcccd34d649ac6654ac1625f459a150176578556629deacc39438dcaad32c73e
    Size: 2.57 MB
  2. ansible-test-2.14.18-3.el9_8.1.ML.1.x86_64.rpm
    MD5: f91b0e2ea54e10f0dc9c5b27e90bb2db
    SHA-256: 85a00fe58c9965f138b6b14bce4590fd747a4770360dfdb6042da93778988a88
    Size: 846.73 kB