Impact
A flaw in the DBI module allows an attacker to execute arbitrary code by influencing the profile attribute passed by a caller. The vulnerability is a code injection flaw (CWE-94), which can compromise both confidentiality and integrity of affected systems. The impact is the execution of any code with the privileges of the running DBI process, potentially leading to full system compromise.
Affected Systems
Red Hat Enterprise Linux 9 and 10 are affected, with the fix applied only for the 9.8.z and 10.2.z release streams. The issue arises from a partial patch for the earlier CVE-2026‑14380, meaning older RHEL 9 and 10 releases remain vulnerable unless updated to the listed releases. No other RHEL versions are explicitly cited, but the presence of Red Hat Enterprise Linux 6, 7, and 8 in the CNA product list suggests that they may also need review for possible exposure.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a trusted process that can set the caller‑influenced profile attribute; the attacker would need to influence or replace that process or supply malicious input via a component leveraging DBI. Because the description does not disclose remote exploitation details, it is inferred that the vulnerability requires local or privileged access to the affected process.
OpenCVE Enrichment