Skip to main content

CVE-2026-91142: Out-of-bounds Write in Red Hat Red Hat Enterprise Linux 10

0
Low
VulnerabilityCVE-2026-91142cvecve-2026-91142
Published: 09/18/2026 (09/18/2026, 16:44:09 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Enterprise Linux 10

Description

A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information.

CVSS v3.1

Score 3.6low

Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected software

Red Hat

Red Hat Enterprise Linux 10

Red Hat

Red Hat Enterprise Linux 7

Red Hat

Red Hat Enterprise Linux 8

Red Hat

Red Hat Enterprise Linux 9

Red Hat

Red Hat OpenShift Dev Spaces

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 17:02:24 UTC

Technical Analysis

This vulnerability involves an integer overflow in the offset calculation for lastlog entries in the do_lastlog() function of Cockpit on ILP32 (32-bit Integer, Long, Pointer) builds. A low-privileged authenticated user with a specially provisioned large UID can cause the offset to wrap around, leading to out-of-bounds reads and writes of lastlog records belonging to other users. This can result in unauthorized disclosure or modification of login accounting data. The issue does not enable code execution or privilege escalation. The vulnerability is tracked as CWE-787 (Out-of-bounds Write).

Potential Impact

The vulnerability allows a low-privileged authenticated user to read and modify lastlog records of other users due to an integer overflow causing offset wraparound. This impacts confidentiality and integrity of login accounting information but does not affect availability or allow privilege escalation or code execution. The attack requires local access and has high complexity, limiting exploitability.

Mitigation Recommendations

Red Hat has published an advisory for CVE-2026-91142. The advisory does not explicitly state that a fix is currently available or deployed. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-91142 for current remediation guidance. Until a fix is available, restrict access to systems to trusted users and monitor for suspicious activity involving lastlog records. No specific mitigations are provided by the vendor advisory beyond awaiting an official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-09-14T20:35:27.812Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-91142","vendor":"Red Hat"}]

Threat ID: 6aad6b0955bf5e2cf541928f

Added to database: 09/18/2026, 16:47:05 UTC

Last enriched: 09/18/2026, 17:02:24 UTC

Last updated: 09/18/2026, 22:45:00 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses