VendorsRed Hatcodeready_linux_builder_for_ibm_z_systemsall versions
Vulnerabilities

Red Hat Codeready Linux Builder For IBM Z Systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2024-1488
Unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
Published 2024-02-15 · Modified
8.0EPSS 0.003
CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
Published 2023-10-03 · Analyzed
7.8KEV1 PoCEPSS 0.814
CVE-2024-0193
Kernel: netfilter: use-after-free in nft_trans_gc_catchall_sync leads to privilege escalation
Published 2024-01-02 · Analyzed
7.8EPSS 0.008
CVE-2023-5633
Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
Published 2023-10-23 · Modified
7.8EPSS 0.003
CVE-2025-13601
Glib: integer overflow in in g_escape_uri_string()
Published 2025-11-26 · Modified
7.7EPSS 0.003
CVE-2021-3737
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Published 2022-03-04 · Modified
7.5EPSS 0.116
CVE-2025-3155
Yelp: arbitrary file read
Published 2025-04-03 · Modified
7.4EPSS 0.142
CVE-2023-3758
Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published 2024-04-18 · Modified
7.1EPSS 0.010
CVE-2025-2784
Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content
Published 2025-04-03 · Modified
7.0EPSS 0.008
CVE-2021-3733
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Published 2022-03-07 · Modified
6.5EPSS 0.047
CVE-2023-4527
Glibc: stack read overflow in getaddrinfo in no-aaaa mode
Published 2023-09-18 · Modified
6.5EPSS 0.017
CVE-2021-3930
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
Published 2022-02-18 · Modified
6.5EPSS 0.003
CVE-2023-4806
Glibc: potential use-after-free in getaddrinfo()
Published 2023-09-18 · Modified
5.9EPSS 0.016
CVE-2020-27842
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
Published 2021-01-05 · Modified
5.5EPSS 0.015
CVE-2023-4042
Ghostscript: incomplete fix for cve-2020-16305
Published 2023-08-23 · Modified
5.5EPSS 0.003
CVE-2023-4641
Shadow-utils: possible password leak during passwd(1) change
Published 2023-12-27 · Modified
5.5EPSS 0.003