Back to Intelligence

openSUSE Advisory 2026-11923-1: openai-codex 0.158.0-1.1 Security Update — Detection and Patching Guide

SA
Security Arsenal Team
October 5, 2026
8 min read

openSUSE has published security advisory 2026-11923-1, pushing openai-codex 0.158.0-1.1 to its repositories. The update resolves two vulnerabilities rated moderate severity in the OpenAI Codex command-line agent — the AI coding assistant that developers increasingly run with broad access to source trees, build pipelines, shell execution, and outbound network connectivity.

The advisory summary is deliberately terse: "An update that solves 2 vulnerabilities can now be installed." No individual CVE identifiers are disclosed in the advisory text, so defenders should treat this as a bundled security maintenance release rather than a response to a single named bug. That said, the affected component deserves your attention regardless of the CVSS label. AI coding agents sit in a uniquely sensitive position in 2026 enterprise environments: they execute shell commands, read and write files across developer workspaces, hold API credentials, and communicate with external model endpoints. A moderate-severity flaw in that execution path — whether it weakens the agent's command sandbox, mishandles untrusted input from a repository or prompt, or exposes session material — is a meaningful risk on any developer workstation or CI runner, and developer machines remain one of the most productive initial-access targets we see in IR engagements.

If your organization runs openSUSE Leap, Tumbleweed, or SUSE-adjacent derivatives with the openai-codex package installed, patch to 0.158.0-1.1 and audit how the agent is being used while you're at it.

Technical Analysis

Affected products and platforms

  • Package: openai-codex
  • Fixed version: 0.158.0-1.1
  • Advisory: openSUSE 2026-11923-1 (linuxsecurity.com advisory listing)
  • Platforms: openSUSE distributions carrying the package (Tumbleweed and Leap channels where the package is published)
  • Severity: Moderate (2 vulnerabilities resolved)

Threat model: why AI coding agents are high-value targets

Even without disclosed CVE specifics, the defensive picture is clear from the component's architecture. The Codex CLI operates as a local execution broker:

  1. It spawns child processes. The agent runs shell commands, compilers, test suites, and package managers on the user's behalf. Any weakness in command validation or sandbox enforcement lets crafted input (e.g., from a malicious repository, README, issue text, or prompt-injected web content) drive unintended local execution.
  2. It holds credentials. API keys for the model provider live in environment variables or config files under the user's home directory. Token theft from developer machines is a standard objective in supply-chain and espionage intrusions.
  3. It has standing network access. The agent maintains outbound HTTPS sessions to model API endpoints. Lookalike endpoints, unexpected egress destinations, or unusual data volumes from the agent process are all meaningful signals.
  4. It runs in CI/CD. Where Codex CLI is embedded in pipelines, a flaw becomes a build-system compromise vector — the same blast radius as any CI credential exposure.

Moderate severity in this class of tool typically maps to issues requiring some local interaction or specific configuration — but on a developer workstation with source access and cloud credentials, the downstream impact of even a conditional flaw is rarely "moderate."

Exploitation status

As of this writing there is no public indication of in-the-wild exploitation, no referenced PoC, and no CISA KEV listing tied to this advisory. The two fixed issues are not individually enumerated in the advisory summary. Treat this as proactive remediation: patch before a researcher or adversary reverse-engineers the diff between the vulnerable and fixed builds, which is standard practice for tooling in this space.

Detection & Response

Because the advisory does not disclose specific indicators, detection content below targets the abuse patterns of the affected component class: the Codex agent spawning unexpected child processes, making anomalous network connections, or its credential/config files being accessed by other processes. These hunts are useful both for post-patch assurance and for catching abuse of AI-agent tooling generally.

YAML
---
title: Codex CLI Agent Spawning Suspicious Child Processes
id: 3c9a7f21-8b2e-4d61-a5c4-9e1f6b2d8a07
status: experimental
description: Detects the openai-codex agent process spawning shells, downloaders, or reconnaissance utilities, which may indicate exploitation of the agent's command execution path or prompt-injection-driven execution.
references:
  - https://linuxsecurity.com/advisories/opensuse/opensuse-2026-11923-1-openai-codex-0-158-0-1-1
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.execution
  - attack.t1059.004
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|contains:
      - '/codex'
      - 'openai-codex'
  selection_child:
    Image|endswith:
      - '/bash'
      - '/sh'
      - '/zsh'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
      - '/socat'
      - '/python'
      - '/python3'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate agent-driven build, test, and dependency-install commands on developer workstations
level: medium
---
title: Sensitive File Access Following AI Agent Execution
id: 6d2b8e14-1f4a-4c79-b3e6-7a5d0c9f2e18
status: experimental
description: Detects processes reading SSH keys, cloud credentials, or Codex/OpenAI API configuration from user home directories shortly after agent execution, consistent with credential harvesting from developer machines.
references:
  - https://attack.mitre.org/techniques/T1552/
  - https://attack.mitre.org/techniques/T1003/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.credential_access
  - attack.t1552.001
logsource:
  category: file_event
  product: linux
detection:
  selection:
    TargetFilename|contains:
      - '/.ssh/id_'
      - '/.aws/credentials'
      - '/.config/gcloud/'
      - '/.codex/'
      - '/.config/openai/'
      - '/.azure/'
  filter_known_tools:
    Image|endswith:
      - '/ssh'
      - '/aws'
      - '/gcloud'
      - '/codex'
      - '/az'
  condition: selection and not filter_known_tools
falsepositives:
  - Backup agents, configuration management, and EDR scanners reading credential paths
level: high
KQL — Microsoft Sentinel / Defender
// Hunt for Codex CLI agent spawning suspicious child processes or establishing
// anomalous outbound connections. Works with Linux Syslog/auditd ingestion or
// MDE onboarding of Linux endpoints.
let SuspiciousChildren = dynamic(["/bin/bash", "/bin/sh", "/usr/bin/curl", "/usr/bin/wget", "/usr/bin/nc", "/usr/bin/python3"]);
let CodexActivity =
    union isfuzzy=true
    (DeviceProcessEvents
    | where InitiatingProcessFileName has_any ("codex", "openai-codex")
    | where FileName has_any ("bash", "sh", "curl", "wget", "nc", "ncat", "socat", "python", "python3")
    | project Timestamp, DeviceName, AccountName, InitiatingProcessCommandLine, FileName, ProcessCommandLine),
    (Syslog
    | where SyslogMessage has "codex"
    | where SyslogMessage has_any ("bash", "curl", "wget", "nc ", "socat", "python")
    | project TimeGenerated, HostName, SyslogMessage);
CodexActivity
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), CommandSamples=make_set(ProcessCommandLine, 5) by DeviceName, AccountName
| order by FirstSeen desc
;
// Companion hunt: Codex agent egress to non-OpenAI endpoints
DeviceNetworkEvents
| where InitiatingProcessFileName has_any ("codex", "openai-codex")
| where not(RemoteUrl has_any ("openai.com", "azure.com", "microsoft.com"))
| summarize Connections=count(), RemoteIPs=make_set(RemoteIP, 10), RemoteURLs=make_set(RemoteUrl, 10) by DeviceName, InitiatingProcessCommandLine
| order by Connections desc
VQL — Velociraptor
-- Hunt for Codex CLI agent processes and their outbound connections
-- Deploy across Linux fleets running openai-codex (e.g., developer workstations, CI runners)

SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)codex'
   OR CommandLine =~ '(?i)openai-codex|/codex'

-- Companion artifact: network connections held by agent processes
SELECT Pid, Name, Status, Family, Type, LocalAddr, LocalPort, RemoteAddr, RemotePort
FROM netstat()
WHERE Name =~ '(?i)codex'
  AND RemoteAddr !~ '^(127\\.|::1$|0\\.0\\.0\\.0)'
Bash / Shell
#!/bin/bash
# Security Arsenal - openSUSE 2026-11923-1 verification and remediation
# Checks installed openai-codex version and applies the fixed build.

FIXED_VERSION="0.158.0-1.1"

echo "[*] Checking for installed openai-codex package..."
INSTALLED=$(rpm -q openai-codex --queryformat '%{VERSION}-%{RELEASE}\n' 2>/dev/null)

if [ -z "$INSTALLED" ]; then
    echo "[+] openai-codex is not installed on this host. No action required."
    exit 0
fi

echo "[*] Installed version: $INSTALLED"

echo "[*] Refreshing repositories and applying update..."
sudo zypper refresh
sudo zypper update -y openai-codex

echo "[*] Verifying patched version..."
NEW_VERSION=$(rpm -q openai-codex --queryformat '%{VERSION}-%{RELEASE}\n' 2>/dev/null)
echo "[*] Now installed: $NEW_VERSION"

if [ "$NEW_VERSION" == "$FIXED_VERSION" ]; then
    echo "[+] SUCCESS: openai-codex is at the fixed build $FIXED_VERSION"
else
    echo "[!] WARNING: installed version ($NEW_VERSION) does not match fixed build ($FIXED_VERSION)"
    echo "[!] Check repository channels: zypper lr -d && zypper info openai-codex"
fi

# Optional hardening: confirm the agent's config and credential paths are not world-readable
echo "[*] Auditing agent credential file permissions..."
for dir in "$HOME/.codex" "$HOME/.config/openai"; do
    if [ -d "$dir" ]; then
        find "$dir" -type f -perm /o+r -exec ls -l {} \;
    fi
done
echo "[*] Done. Any files listed above are world-readable and should be chmod 600."

Remediation

  1. Patch immediately to openai-codex 0.158.0-1.1. Use sudo zypper update openai-codex on affected openSUSE systems. Confirm the build with rpm -q openai-codex. Prioritize developer workstations, shared build hosts, and CI runners where the agent executes with elevated or credential-rich context.
  2. Inventory where the agent is actually deployed. Most organizations do not have a clean inventory of AI coding assistants. Query your package management data (or EDR software inventory) for openai-codex and equivalent tooling. You cannot patch what you have not catalogued.
  3. Rotate exposed credentials on high-risk hosts. If a vulnerable build was running on machines with cloud, repository, or API access, rotate the OpenAI API keys stored under ~/.codex/ or ~/.config/openai/ and review adjacent credentials (SSH keys, .aws/credentials) as a precaution.
  4. Constrain agent execution. Run the Codex CLI with its sandbox/approval mode enabled rather than full auto-execution, and avoid running it as root or on shared CI images with long-lived secrets. Scope API keys to minimum required permissions.
  5. Monitor egress. Alert on the agent process communicating with endpoints outside the expected model provider domains — this is a durable control that outlives any single patch.
  6. Fold AI tooling into your vulnerability management SLA. Treat AI agents as first-class attack surface in your VM program: tracked in asset inventory, covered by patch SLAs proportionate to their access, and included in tabletop scenarios for developer-machine compromise.

No CISA KEV entry or vendor-mandated deadline applies to this advisory at the time of writing. The reference advisory listing is available at the LinuxSecurity openSUSE advisory page.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.