Database/Control plane, storage & DevOps
Ansible automation-controller: unvalidated system-job "days" value injects arguments into control-node awx-manage
Impact
The system-job launch endpoint stores a user-supplied days value without the integer validation defined for that field, and the dispatcher joins management-command arguments into one space-separated string before the runner re-splits it, so spaces become extra command-line arguments. System jobs run in-process on the control node without the container isolation applied to every other job type, so the injected arguments land in the control-plane awx-manage process and can control its argument vector and the first entry of its Python module search path. Red Hat notes that full remote code execution needs an import gadget not present in the current management commands, so the demonstrated impact is argument injection with search-path control, not confirmed execution. For an operator using AAP to drive fleet configuration, a compromise of the control node reaches every managed GPU host, which is why the CVSS vector marks scope changed.
Who can reach it
Network-reachable automation-controller API, authenticated as a superuser. That is a high-privilege account already, which is why the score stays moderate - the value is the escape from the container isolation that constrains normal jobs.
What to do
Apply the automation-controller errata (RHSA-2026:71113, 71114, 71177, 71179) for your AAP 2.5/2.6/2.7 channel and restart the controller services; no managed-node reboot or fleet drain is needed. Until patched, keep the superuser population minimal and audited, since that is the only precondition.
References
Related entries
- HTCondor (condor_schedd, GSI/VOMS extension parsing): An authenticated user crashes the schedd by feeding it malformedCVE-2017-16816 · HTCondor (condor_schedd, GSI/VOMS extension parsing)Medium
- GlusterFS (dict_unserialize): A negative key length in a serialized dict makes the server read memory from elsewhere inCVE-2018-10911 · GlusterFS (dict_unserialize)Medium
- Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alterCVE-2018-1129 · Ceph CephX authentication protocolMedium
- Intel Core and Xeon CPUs - INTEL-SA-00210: This one is availability, not confidentiality, and it is the mostCVE-2018-12207 · Intel Core and Xeon CPUs - INTEL-SA-00210Medium
- Nouveau display driver (in-tree Linux nouveau, NV117): Remote denial of service against a workstation or node runningCVE-2018-3979 · Nouveau display driver (in-tree Linux nouveau, NV117)Medium
- Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270: Same class of in-flight data leakCVE-2019-11135 · Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.