What is CVE-2026-47192?
CVE-2026-47192 is a vulnerability found in the `kas` setup tool used for `bitbake` based projects. In versions 4.8 to 5.3, it checks out and processes repositories for configuration includes before validating their signatures, potentially allowing an attacker to replace the original repository with a malicious one. Users should review the vendor advisory for patching guidance as no specific version details were provided in the report.
Azərbaycanca: CVE-2026-47192 kibertəhlükəsizlik zəifliyi `kas` alətində aşkarlanıb. Bu, `bitbake` əsaslı layihələr üçün konfiqurasiya alətidir. 4.8-dən 5.3-ə qədər olan versiyalarda, o, repozitoriyaların imzalarını yoxlamazdan əvvəl onları yoxlayır və işləyir ki, bu da orijinal repozitoriyanın zərərli biri ilə əvəzlənməsinə səbəb ola bilər.
FAQ2
Which tool is affected by CVE-2026-47192?
This vulnerability affects the `kas` setup tool used for `bitbake` based projects.
What is the root cause of CVE-2026-47192?
The cause is the tool checking out and processing repositories for configuration includes before validating their signatures.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.