#2110 [cockpit] CVE-2026-4631 cockpit: Cockpit: Unauthenticated remote code execution due to SSH command-line argument injection | rhbz#2458620
Closed by blockerbot. Opened by blockerbot.

Bug details: ** https://bugzilla.redhat.com/show_bug.cgi?id=2458620 **
Information from BlockerBugs App:
2458620

Current vote summary

The votes have been last counted at 2026-04-15 14:49 UTC and the last processed comment was #comment-1011390

To learn how to vote, see:
https://pagure.io/fedora-qa/blocker-review
A quick example: BetaBlocker +1 (where the tracker name is one of BetaBlocker/FinalBlocker/BetaFE/FinalFE/0Day/PreviousRelease and the vote is one of +1/0/-1)


The release must contain no known security bugs of 'important' or higher impact according to the Red Hat severity classification scale. This CVE is critical so

FinalBlocker +1

FinalBlocker +1

FinalBlocker +1

This would leave every Fedora Server initial installation in a state vulnerable to a relatively easy-to-exploit remote code execution bug.

FinalBlocker +1
AGREED AcceptedFinalBlocker

The following votes have been closed:

Metadata Update from @blockerbot:
- Issue status updated to: Closed (was: Open)

Release F44 is no longer tracked by BlockerBugs, closing this ticket.

Metadata