live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsSECURITY

RHEL 8 update closes an urwid session flaw that can lead to remote code execution

Red Hat rates CVE-2026-9323 Important and advises users to patch—or restrict the web display backend while they do.

Huge patch fix for a vulnerable terminal backend.
AI-generated illustration
By The News Desk· Aug 24, 2026

Red Hat has shipped updated python-urwid packages for Red Hat Enterprise Linux 8 to close a predictable-session-ID flaw in urwid’s web display backend. RHSA-2026:58562, issued August 24, rates the update Important and lists RHEL 8 across x86_64, Arm 64, IBM Z and Power, including RHEL 8.10 Extended Life Cycle channels, as affected.

What changed

The flaw, CVE-2026-9323, comes from using a cryptographically insecure pseudorandom-number generator for web-session identifiers. Red Hat says a remote attacker can observe enough identifiers to reconstruct the generator’s state; a local attacker can instead enumerate active session tokens from temporary files.

A successful attack can expose a victim’s terminal screen, inject keystrokes with the victim’s privileges or terminate the session. Red Hat assigns the issue a CVSS 3.1 base score of 8.1, with a network attack vector, no required privileges and no user interaction, while noting that exploitation has high attack complexity.

The fixed RHEL 8 build is python-urwid-1.3.1-5.el8_10, according to the advisory. Red Hat provides updated packages for all listed architectures and directs customers to apply the security update through their normal RHEL patching process.

Who is affected

The vulnerable path is specifically urwid’s web display backend, not every terminal interface built with urwid. Teams should prioritize systems that expose that backend over a network or use it for privileged operational consoles. The Red Hat CVE record says exploitation can reach operating-system-level code execution with the victim’s privileges.

The advisory covers standard RHEL 8 channels as well as RHEL 8.10 Extended Life Cycle channels. Administrators can use Red Hat Lightspeed patch analysis from the advisory to identify affected subscribed systems.

What to do

Apply RHSA-2026:58562 and verify that installed python3-urwid packages come from the updated build. If patching cannot happen immediately, Red Hat recommends disabling the urwid web display backend when it is not essential.

Where the backend must remain available, Red Hat’s mitigation guidance is to restrict network access to trusted clients with firewall rules and prevent unauthorized local access to temporary files containing active tokens. Configuration changes may require restarting the service. Those controls reduce exposure, but the package update is the durable fix.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.