Critical Memory Leak Vulnerability in Fedora Cockpit

Critical Memory Leak Vulnerability in Fedora Cockpit

First seen 4 Sep 2026, 08:45 UTC Linuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

A significant memory leak vulnerability, identified as CVE-2026-76235, affects the Cockpit Web Console in Fedora systems. This flaw allows unauthenticated remote users to exploit the CockpitLang cookie, potentially leading to unauthorized access to sensitive information. The vulnerability was published on August 19, 2026, and impacts both Fedora 43 and 44 versions. Users are urged to apply the latest updates to mitigate the risk. The flaw affects all Fedora installations utilizing the Cockpit Web Console. The latest updates for Fedora 44 and 43 were released on September 2 and September 4, respectively, to address this issue. Administrators can install the updates using the 'dnf' package manager. The situation remains critical as the vulnerability could be exploited if not patched promptly.

Key Points: • CVE-2026-76235 allows unauthenticated remote memory leaks in Cockpit. • Affected versions include Fedora 43 and 44, requiring immediate patching. • Updates were released on September 2 and 4, 2026, to address the vulnerability.

Ask AI about this cluster

Timeline

2026-08-19
CVE-2026-76235 published
A memory leak vulnerability in Cockpit Web Console was disclosed, affecting Fedora systems.
Linuxsecurity
2026-09-02
Fedora 44 update released
An update for Fedora 44 was released to fix the memory leak vulnerability in Cockpit.
Linuxsecurity
2026-09-04
Fedora 43 update released
An update for Fedora 43 was released to address the same memory leak vulnerability in Cockpit.
Linuxsecurity