Changeflow GovPing Data Privacy & Cybersecurity Red Hat Enterprise Linux ncurses Vulnerability ...
Priority review Notice Amended Final

Red Hat Enterprise Linux ncurses Vulnerability Allows Code Execution

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 25th, 2026
Detected March 26th, 2026
Email

Summary

CERT-Bund has issued an advisory for a vulnerability in Red Hat Enterprise Linux (ncurses) that allows local attackers to execute arbitrary code. The advisory assigns a CVSS Base Score of 7.3 (high) and a Temporal Score of 6.4 (medium). Mitigation is available.

What changed

CERT-Bund has released an advisory (WID-SEC-2026-0875) detailing a critical vulnerability in Red Hat Enterprise Linux (RHEL) related to the ncurses component. This vulnerability, assigned a CVSS Base Score of 7.3, allows local attackers to execute arbitrary program code on affected systems. The advisory indicates that mitigation measures are available.

Organizations using Red Hat Enterprise Linux, particularly version 10, should immediately review their systems for potential exposure. Compliance officers should coordinate with IT security teams to apply available mitigations and patches to prevent unauthorized code execution. While this is a notice and not a direct regulatory mandate, failure to address such vulnerabilities can lead to significant security breaches, data loss, and potential regulatory scrutiny under broader cybersecurity frameworks.

What to do next

  1. Review Red Hat Enterprise Linux systems for the ncurses vulnerability.
  2. Apply available mitigations and patches as recommended by CERT-Bund and Red Hat.
  3. Coordinate with IT security to assess and remediate affected systems.

Source document (simplified)

[WID-SEC-2026-0875] Red Hat Enterprise Linux (ncurses): Schwachstelle ermöglicht Codeausführung CVSS Base Score 7.3 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff nein Datum 25.03.2026 Stand 26.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Linux

Produktbeschreibung

Red Hat Enterprise Linux (RHEL) ist eine populäre Linux-Distribution.

Produkte

25.03.2026
- Red Hat Enterprise Linux 10

Angriff

Angriff

Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (ncurses) ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 25th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-0875

Who this affects

Applies to
Employers
Industry sector
5112 Software & Technology
Activity scope
Vulnerability Management
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Vulnerability Management Software Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.