CVE-2026-103431 PUBLISHED

Collectl: collectl: colmux does not sanitize ansi/vt100 terminal escape sequences in data received from remote collectl instances

Assigner: fedora
Reserved: 30.09.2026 Published: 01.10.2026 Updated: 01.10.2026

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 7.7

Product Status

Package Collection https://github.com/sharkcz/collectl
Package Name collectl
Versions Default: unaffected
  • affected from 0 to 4.3.20.3 (excl.)

Workarounds

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Credits

  • This issue was discovered by Laurence Oberman (Red Hat) and Nathan Scott (Red Hat).

References

Problem Types

  • Improper Neutralization of Escape, Meta, or Control Sequences CWE