Improper Resource Locking Affecting flightctl-agent package, versions *


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.13% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-FLIGHTCTLAGENT-19876726
  • published17 Sept 2026
  • disclosed16 Sept 2026

Introduced: 16 Sep 2026

NewCVE-2026-92615  (opens in a new tab)
CWE-413  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:10 flightctl-agent.

NVD Description

Note: Versions mentioned in the description apply only to the upstream flightctl-agent package and not the flightctl-agent package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates) and installs it into go-git's process-global client.Protocols map via gitclient.InstallProtocol("https", ...). Because the worker renders devices for multiple organizations concurrently from a shared goroutine pool, whichever tenant's repository configuration is written last wins for all in-flight git.Clone calls. This race condition can cause one tenant's TLS settings, including InsecureSkipVerify or mTLS client credentials, to leak into another tenant's git operations.

CVSS Base Scores

version 3.1