Red Hat Product Errata RHSA-2026:49758 - Security Advisory Issued: 2026-08-03 Updated: 2026-08-03 RHSA-2026:49758 - Security Advisory Overview Updated Packages Synopsis Critical: perl-GD security update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for perl-GD is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is a autoloadable interface module for GD, a popular library for creating and manipulating PNG files. With this library you can create PNG images on the fly or modify existing files. Security Fix(es): perl-GD: perl-GD: Arbitrary command execution and file overwrite via crafted filenames (CVE-2026-11526) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le Fixes BZ - 2488744 - CVE-2026-11526 perl-GD: perl-GD: Arbitrary command execution and file overwrite via crafted filenames CVEs CVE-2026-11526 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 SRPM perl-GD-2.49-3.el7_9.1.src.rpm SHA-256: 6bd347c3a6b79695d0a92367f69c4cb5af2b3a7deb796da3dca8f824abd8192a x86_64 perl-GD-2.49-3.el7_9.1.x86_64.rpm SHA-256: 4fe90199e32b90524eb0fc24a9718624edb4a4b6e28a5d76b79fe26e84e4094d perl-GD-debuginfo-2.49-3.el7_9.1.x86_64.rpm SHA-256: 3b4dfcbf94c4c3d2b7e9309cf5bff943be1975319c1573720245b4ca51ce13f6 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 SRPM perl-GD-2.49-3.el7_9.1.src.rpm SHA-256: 6bd347c3a6b79695d0a92367f69c4cb5af2b3a7deb796da3dca8f824abd8192a s390x perl-GD-2.49-3.el7_9.1.s390x.rpm SHA-256: 630d0347574cec82a497a7845057bc3e5c36f0cd24d38c34ce1bb10bbdde8d22 perl-GD-debuginfo-2.49-3.el7_9.1.s390x.rpm SHA-256: 50f1bc8c741cc7238e66ff31050ddba14a6eb911a52aabd6d9a5ad0a632e6461 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 SRPM perl-GD-2.49-3.el7_9.1.src.rpm SHA-256: 6bd347c3a6b79695d0a92367f69c4cb5af2b3a7deb796da3dca8f824abd8192a ppc64 perl-GD-2.49-3.el7_9.1.ppc64.rpm SHA-256: c8c034a22cac508636308a2b4c82b72b279e55b893c172265b55cad01783857d perl-GD-debuginfo-2.49-3.el7_9.1.ppc64.rpm SHA-256: 86cb6394e1dd63ede164bf818a30971ac19b1a16b95ad8527045f8655fc79d98 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 SRPM perl-GD-2.49-3.el7_9.1.src.rpm SHA-256: 6bd347c3a6b79695d0a92367f69c4cb5af2b3a7deb796da3dca8f824abd8192a ppc64le perl-GD-2.49-3.el7_9.1.ppc64le.rpm SHA-256: feacfc481066ce81a7287cb75ee745cdbbce3d1faf9ae38d934d5c1878125bbc perl-GD-debuginfo-2.49-3.el7_9.1.ppc64le.rpm SHA-256: b6bb17ec2d0dcaccb1ff4cc5ef7069fc07831a1d1f9b20fc6a56ee38eaeb1572 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A critical vulnerability (CVE-2026-11526, CVSS 9.8) in the perl-GD library allows arbitrary command execution and file overwrite through the processing of crafted filenames. The security update addresses this flaw for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Affected systems should apply the provided patch, specifically updating to perl-GD version 2.49-3.el7_9.1.