wget-1.21.1-11.el9_8

エラータID: AXSA:2026-1757:02

Release date: 
Friday, September 4, 2026 - 13:57
Subject: 
wget-1.21.1-11.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The wget packages provide the GNU Wget file retrieval utility for HTTP, HTTPS, and FTP protocols.

Security Fix(es):

* wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption (CVE-2026-58471)
* wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute (CVE-2026-58472)

Bug Fix(es) and Enhancement(s):

* wget async unsafe code in signal handler context [rhel-9.8.z] (JIRA:RHEL-220497)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-58471
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
CVE-2026-58472
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. wget-1.21.1-11.el9_8.src.rpm
    MD5: dfc386a49600f61263e44ccb5358a934
    SHA-256: d4b1a596d0abf6c0d7720902005058687aa3b9dc46473e43fb46ef71fea8422a
    Size: 4.68 MB

Asianux Server 9 for x86_64
  1. wget-1.21.1-11.el9_8.x86_64.rpm
    MD5: af18fc3a896abaee7ce45fc6c44cc117
    SHA-256: 94ad4035dcfda5df1f9b14259b3d28c99ca12a1c44f238b676d5525683224d1f
    Size: 787.57 kB