[ALSA-2026:62144] Moderate: wget security, bug fix, and enhancement update
Type:
security
Severity:
moderate
Release date:
2026-09-02
Description:
The wget packages provide the GNU Wget file retrieval utility for HTTP, HTTPS, and FTP protocols. Security Fix(es): * wget: GNU Wget: Memory corruption via crafted Metalink URL (CVE-2026-58469) * wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption (CVE-2026-58471) * wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute (CVE-2026-58472) Bug Fix(es) and Enhancement(s): * wget async unsafe code in signal handler context [almalinux-8.10.z] (JIRA:AlmaLinux-145875) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 wget-1.19.5-16.el8_10.aarch64.rpm 019863c8f3b9ad86cc9137cf1280e5bee7cb4400f5f432504553def797adc272
ppc64le wget-1.19.5-16.el8_10.ppc64le.rpm 9532075308646e6a20ebe80224a1845f3b550dbf03afc63ab01b13b20aefdb1e
s390x wget-1.19.5-16.el8_10.s390x.rpm a16696fdb50bf5527d6d6e4d1241c23d1119763dee3706c93ecd28b4cc5ceedb
x86_64 wget-1.19.5-16.el8_10.x86_64.rpm 0db4bbfb4480fb1abdfceb8f90987b751d9dfc6cc34af9865f49ebc87a27ebfa
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.