Description
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information.
Published: 2026-09-18
Score: 3.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized read/write to other users' lastlog entries
Action: Apply patch
AI Analysis

Impact

An integer overflow occurs in the offset calculation performed by the do_lastlog() function when Cockpit is executed on ILP32 (32‑bit integer, long, pointer) builds. The flaw allows a low‑privileged authenticated user who has been granted a specially large User ID to cause the calculated offset to wrap around. The victim can then read from and overwrite other users' lastlog records, potentially exposing or altering sensitive login accounting information. No exploitation of system privilege escalation or remote code execution is indicated by the supplied data.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux 7, 8, 9, and 10, as well as Red Hat OpenShift Dev Spaces 3. Exact version numbers are not listed in the CNA data; the build type (ILP32) is the determining factor for whether the impact applies.

Risk and Exploitability

The CVSS score of 3.6 indicates a moderate level of risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests it is not widely exploited as of the latest data. Attackers need a locally authenticated account and the ability to assign large UIDs to invoke the overflow, so the vector is largely limited to local, enterprise environments that use 32‑bit builds of Cockpit. The primary threat is the unauthorized disclosure or modification of lastlog entries rather than escalated privileges or remote compromise.

Generated by OpenCVE AI on September 19, 2026 at 12:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a later Cockpit release that resolves the overflow whenever one is made available by Red Hat.
  • Verify whether your Cockpit installation uses an ILP32 build; the vulnerability does not affect 64‑bit builds.
  • Implement UID limits on your system—configure login.defs or PAM limits modules to disallow UIDs that exceed the safe threshold, thereby preventing the large UID required to trigger the overflow.

Generated by OpenCVE AI on September 19, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Dev Spaces
Vendors & Products Redhat openshift Dev Spaces

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information.
Title Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift Devspaces
Weaknesses CWE-787
CPEs cpe:/a:redhat:openshift_devspaces:3
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift Devspaces
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Enterprise Linux Openshift Dev Spaces Openshift Devspaces
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-18T17:09:57.106Z

Reserved: 2026-09-14T20:35:27.812Z

Link: CVE-2026-91142

cve-icon Vulnrichment

Updated: 2026-09-18T17:09:51.291Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T17:17:05.283

Modified: 2026-09-18T19:06:08.407

Link: CVE-2026-91142

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-18T16:27:00Z

Links: CVE-2026-91142 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:14Z

Weaknesses