Red Hat Enterprise Linux ncurses Vulnerability Allows Code Execution
Summary
CERT-Bund has issued an advisory for a vulnerability in Red Hat Enterprise Linux (ncurses) that allows local attackers to execute arbitrary code. The advisory assigns a CVSS Base Score of 7.3 (high) and a Temporal Score of 6.4 (medium). Mitigation is available.
What changed
CERT-Bund has released an advisory (WID-SEC-2026-0875) detailing a critical vulnerability in Red Hat Enterprise Linux (RHEL) related to the ncurses component. This vulnerability, assigned a CVSS Base Score of 7.3, allows local attackers to execute arbitrary program code on affected systems. The advisory indicates that mitigation measures are available.
Organizations using Red Hat Enterprise Linux, particularly version 10, should immediately review their systems for potential exposure. Compliance officers should coordinate with IT security teams to apply available mitigations and patches to prevent unauthorized code execution. While this is a notice and not a direct regulatory mandate, failure to address such vulnerabilities can lead to significant security breaches, data loss, and potential regulatory scrutiny under broader cybersecurity frameworks.
What to do next
- Review Red Hat Enterprise Linux systems for the ncurses vulnerability.
- Apply available mitigations and patches as recommended by CERT-Bund and Red Hat.
- Coordinate with IT security to assess and remediate affected systems.
Source document (simplified)
[WID-SEC-2026-0875] Red Hat Enterprise Linux (ncurses): Schwachstelle ermöglicht Codeausführung CVSS Base Score 7.3 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff nein Datum 25.03.2026 Stand 26.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
Produktbeschreibung
Red Hat Enterprise Linux (RHEL) ist eine populäre Linux-Distribution.
Produkte
25.03.2026
- Red Hat Enterprise Linux 10
Angriff
Angriff
Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (ncurses) ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.