Rocky Linux 8 and 9 Vulnerabilities Lead to Remote Code Execution Risks

Rocky Linux 8 and 9 Vulnerabilities Lead to Remote Code Execution Risks

First seen 2 Sep 2026, 13:13 UTC Linuxsecurity 58.5

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities have been identified in Rocky Linux affecting both version 8 and 9. Specifically, Rocky Linux 9 is impacted by a remote code execution vulnerability in gegl04 (CVE-2026-62170) and a moderate denial of service issue in libssh (CVE-2026-62217). Rocky Linux 8 also faces moderate denial of service issues in libssh (CVE-2026-62218) and a memory corruption vulnerability in wget (CVE-2026-62144). All vulnerabilities have been assigned CVSS scores indicating their severity, and updates are available for affected packages. Administrators are urged to apply patches promptly to mitigate risks. The vulnerabilities could allow attackers to execute arbitrary code or cause service disruptions. The updates are crucial for maintaining system integrity and security.

Key Points: • Rocky Linux 9 has critical vulnerabilities in gegl04 and libssh requiring immediate patching. • Rocky Linux 8 is affected by similar vulnerabilities in libssh and wget, also needing updates. • All vulnerabilities have CVEs assigned and patches are available for affected systems.

Timeline

2026-09-02
Rocky Linux 9 gegl04 vulnerability disclosed
CVE-2026-62170 identified in gegl04 allowing remote code execution on Rocky Linux 9.
Linuxsecurity
2026-09-02
Rocky Linux 9 libssh denial of service vulnerability disclosed
CVE-2026-62217 reported in libssh affecting Rocky Linux 9, leading to service disruptions.
Linuxsecurity
2026-09-02
Rocky Linux 8 libssh denial of service vulnerability disclosed
CVE-2026-62218 found in libssh for Rocky Linux 8, posing a moderate risk of denial of service.
Linuxsecurity
2026-09-02
Rocky Linux 8 wget memory corruption vulnerability disclosed
CVE-2026-62144 identified in wget for Rocky Linux 8, allowing potential code execution.
Linuxsecurity