ALSA-2026:18480

Source
https://errata.almalinux.org/10/ALSA-2026-18480.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:18480.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALSA-2026:18480
Related
Published
2026-05-19T00:00:00Z
Modified
2026-05-26T16:59:13.877695905Z
Summary
Important: linux-sgx security update
Details

The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.

Security Fix(es):

  • qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)
  • node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)
  • node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)
  • lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  • node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

References

Affected packages

AlmaLinux:10
sgx-common

Package

Name
sgx-common
Purl
pkg:rpm/almalinux/sgx-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:18480.json"
sgx-libs

Package

Name
sgx-libs
Purl
pkg:rpm/almalinux/sgx-libs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:18480.json"
sgx-mpa

Package

Name
sgx-mpa
Purl
pkg:rpm/almalinux/sgx-mpa

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:18480.json"
sgx-pccs

Package

Name
sgx-pccs
Purl
pkg:rpm/almalinux/sgx-pccs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:18480.json"
sgx-pccs-admin

Package

Name
sgx-pccs-admin
Purl
pkg:rpm/almalinux/sgx-pccs-admin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:18480.json"
sgx-pckid-tool

Package

Name
sgx-pckid-tool
Purl
pkg:rpm/almalinux/sgx-pckid-tool

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:18480.json"
tdx-qgs

Package

Name
tdx-qgs
Purl
pkg:rpm/almalinux/tdx-qgs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.26-7.el10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:18480.json"