ansible-core-2.16.3-4.el8_10.ML.1

エラータID: AXSA:2026-1818:04

Release date: 
Monday, September 14, 2026 - 18:08
Subject: 
ansible-core-2.16.3-4.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.

Security Fix(es):

* ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-11332
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ansible-core-2.16.3-4.el8_10.ML.1.src.rpm
    MD5: cf3800b134e707c006c8fa1e6c4b33be
    SHA-256: d6c93bde96203313f20475698fdd6efa5299789e23d62afa6aae80ecdc2cc519
    Size: 8.31 MB

Asianux Server 8 for x86_64
  1. ansible-core-2.16.3-4.el8_10.ML.1.x86_64.rpm
    MD5: 033a5c66950906a13bab494166230cdc
    SHA-256: 975e71a80689e00bc83b38ab9f2608e64f9fc0acc601a7ca968875feb7bcccf3
    Size: 3.63 MB
  2. ansible-test-2.16.3-4.el8_10.ML.1.x86_64.rpm
    MD5: e426113dd7797548182221edef80d819
    SHA-256: cba7b16bbcb5ec81e91fbe77dd45bb5921b69de6fe64cb226926d659d761e066
    Size: 944.72 kB