Rocky Linux 8 Faces Critical Vulnerabilities in xmlrpc-c and Redis

Rocky Linux 8 Faces Critical Vulnerabilities in xmlrpc-c and Redis

First seen 9 Sep 2026, 14:44 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

On September 9, 2026, two significant vulnerabilities were disclosed affecting Rocky Linux 8. The first involves xmlrpc-c, which has a critical cross-site scripting vulnerability. The second pertains to Redis, which has important remote code execution issues. Both vulnerabilities have received a Common Vulnerability Scoring System (CVSS) base score indicating their severity. The xmlrpc-c vulnerability allows attackers to execute scripts in the context of the user’s session, while the Redis vulnerability could allow remote code execution. Users of Rocky Linux 8 are urged to apply the patches immediately to mitigate these risks. Specific package versions affected include xmlrpc-c 1.51.0 and Redis 6.2.24. The updates are available for multiple architectures including aarch64 and x86_64. Security professionals should prioritize these updates to safeguard their systems against potential exploitation.

Key Points: • Rocky Linux 8 has critical vulnerabilities in xmlrpc-c and Redis. • The xmlrpc-c vulnerability allows cross-site scripting attacks. • The Redis vulnerability could lead to remote code execution.

Ask AI about this cluster

Timeline

2026-09-09
Vulnerabilities disclosed for Rocky Linux 8
Critical vulnerabilities in xmlrpc-c and Redis were disclosed, affecting Rocky Linux 8 systems.
Linuxsecurity
2026-09-09
Patches released for xmlrpc-c and Redis
Updates for xmlrpc-c and Redis were made available, addressing the critical vulnerabilities.
Linuxsecurity