Critical [CVE-2026-44170] Arbitrary shell command execution via improper sanitization in CONNECT engine
This critical-severity Red Hat Linux advisory covers CVE-2026-44170 affecting Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Arbitrary shell command execution via improper sanitization in CONNECT engine. Red Hat rates this important (CVSS 9.9).
Weakness: CWE-78. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11.
Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`).
Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat Enterprise Linux 10.0 Extended Update Support.
- mariadb10.11-3:10.11.18-1.el10_2
- mariadb11-8-main-11.8.8-1.hum1
- galera-0:26.4.27-1.el10_2
- mariadb:11.8-9080020260612104015.rhel9
- mariadb11.8-3:11.8.8-1.el10_2
- mariadb:10.11-8100020260616102001.489197e6
- mariadb:10.11-9080020260612103452.rhel9
- mariadb10-11-main-10.11.18-1.hum1
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
- RHSA-2026:33093
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
Mitigation checklist
- Update the affected package(s) to the fixed version shipped in RHSA-2026:33093 (`sudo dnf update` / `yum update`).
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.