How to Fix CVE-2026-6862: Red Hat Enterprise Linux 10 (Bundle Sibling)
By Sai Kiran Pandrala
Last verified: 2026-05-25
CVE-2026-6862 is a sibling vulnerability in the same vendor advisory as CVE-2026-2708. Applying the patched build named in the primary write-up closes this CVE as well.
| Severity | CVSS 5.5 - Medium |
|---|---|
| Actively exploited? | Not currently in CISA KEV |
| Affected | Same as the bundle - see CVE-2026-2708 |
| Fixed in | Same patched build as CVE-2026-2708 (See vendor advisory) |
| Type (CWE) | CWE-674: Uncontrolled Recursion |
What's different about CVE-2026-6862?
A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) device path node header. A local user could exploit this vulnerability by providing a specially crafted device path node. This can lead to infinite recursion, causing stack exhaustion and a process crash, resulting in a denial of service (DoS).
The technical impact and remediation are identical to the primary CVE in the bundle. The same vendor patch closes both.
How to fix CVE-2026-6862
Apply the patched build per the primary write-up: How to Fix CVE-2026-2708.
The patch installation procedure, verification commands, and interim mitigations are documented there. Reusing one runbook keeps the rollout consistent across the bundle.
Frequently asked questions
Is CVE-2026-6862 fixed by the same patch as CVE-2026-2708?
Yes. CVE-2026-6862 ships in the same vendor advisory as CVE-2026-2708. Applying the patched build named in the primary write-up closes both.
What is the CVSS score for CVE-2026-6862?
The CVSS base score is 5.5 (Medium).
Is it being exploited?
It is not currently listed in CISA KEV.
References
- Official vendor advisory: https://access.redhat.com/security/cve/CVE-2026-6862
- NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-6862
- CISA KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Primary write-up: How to Fix CVE-2026-2708
*Part of the Red Hat Enterprise Linux 10 bundle. Full procedure at CVE-2026-2708.*