wget-1.19.5-16.el8_10

エラータID: AXSA:2026-1745:01

Release date: 
Thursday, September 3, 2026 - 14:42
Subject: 
wget-1.19.5-16.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The wget packages provide the GNU Wget file retrieval utility for HTTP, HTTPS, and FTP protocols.

Security Fix(es):

* wget: GNU Wget: Memory corruption via crafted Metalink URL (CVE-2026-58469)
* wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption (CVE-2026-58471)
* wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute (CVE-2026-58472)

Bug Fix(es) and Enhancement(s):

* wget async unsafe code in signal handler context [rhel-8.10.z] (JIRA:RHEL-145875)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-58469
GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.
CVE-2026-58471
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
CVE-2026-58472
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. wget-1.19.5-16.el8_10.src.rpm
    MD5: 2b6ec09668cdb3135916ae408804f9c4
    SHA-256: 4fc909956f52568590ef3a3cc5ab6314a1d24866be592ecbb047ee470c1bf294
    Size: 4.30 MB

Asianux Server 8 for x86_64
  1. wget-1.19.5-16.el8_10.x86_64.rpm
    MD5: b54a4cf271eb97f78aba0743f9b1a5a9
    SHA-256: 0ed78de9ea99693c5f8866af08c1cee672848abe607e2d32af0c1a84fe054d4d
    Size: 734.11 kB