PT-2026-48375 · Red Hat · Red Hat Enterprise Linux 10+4
Published
2026-06-10
·
Updated
2026-06-10
·
CVE-2026-11837
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
A local privilege escalation vulnerability was found in the ansible.posix authorized key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized key task as root, leading to local privilege escalation.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Red Hat Openstack Platform 17.1
Red Hat Openstack Platform 18.0