VendorsRed Hatenterprise_linux9.0
Vulnerabilities

Red Hat Enterprise Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

601CVEs
CVE-2022-1016
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.
Published 2022-08-29 · Modified
5.5EPSS 0.004
CVE-2022-1198
A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space.
Published 2022-08-29 · Modified
5.5EPSS 0.004
CVE-2023-2731
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
Published 2023-05-17 · Modified
5.5EPSS 0.004
CVE-2022-3821
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Published 2022-11-08 · Modified
5.5EPSS 0.004
CVE-2023-42754
Kernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()
Published 2023-10-05 · Modified
5.5EPSS 0.004
CVE-2026-5704
Tar: tar: hidden file injection via crafted archives
Published 2026-04-06 · Modified
5.5EPSS 0.004
CVE-2023-6228
Libtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.c
Published 2023-12-18 · Modified
5.5EPSS 0.004
CVE-2023-40550
Shim: out-of-bound read in verify_buffer_sbat()
Published 2024-01-29 · Modified
5.5EPSS 0.004
CVE-2023-1981
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
Published 2023-05-26 · Modified
5.5EPSS 0.004
CVE-2024-0232
Sqlite: use-after-free bug in jsonparseaddnodearray
Published 2024-01-16 · Modified
5.5EPSS 0.004
CVE-2023-43788
Libxpm: out of bounds read in xpmcreatexpmimagefrombuffer()
Published 2023-10-10 · Modified
5.5EPSS 0.004
CVE-2023-43789
Libxpm: out of bounds read on xpm with corrupted colormap
Published 2023-10-12 · Modified
5.5EPSS 0.004
CVE-2023-3576
Libtiff: memory leak in tiffcrop.c
Published 2023-10-04 · Modified
5.5EPSS 0.003
CVE-2026-3632
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
Published 2026-03-17 · Analyzed
5.5EPSS 0.003
CVE-2026-6695
Gimp: gimp: remote code execution via crafted paa file
Published 2026-08-03 · Analyzed
5.5EPSS 0.003
CVE-2026-59088
Gimp: gimp: denial of service via signed integer overflow in fli file processing
Published 2026-08-10 · Analyzed
5.5EPSS 0.003
CVE-2023-6622
Kernel: null pointer dereference vulnerability in nft_dynset_init()
Published 2023-12-08 · Analyzed
5.5EPSS 0.003
CVE-2024-0408
Xorg-x11-server: selinux unlabeled glx pbuffer
Published 2024-01-18 · Modified
5.5EPSS 0.003
CVE-2023-3164
Heap-buffer-overflow in extractimagesection()
Published 2023-11-02 · Modified
5.5EPSS 0.003
CVE-2022-2873
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.
Published 2022-08-22 · Modified
5.5EPSS 0.003
CVE-2023-6679
Kernel: null pointer dereference in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c
Published 2023-12-11 · Modified
5.5EPSS 0.003
CVE-2022-1852
A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.
Published 2022-06-30 · Modified
5.5EPSS 0.003
CVE-2024-0690
Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
Published 2024-02-06 · Modified
5.5EPSS 0.003
CVE-2023-7192
Kernel: refcount leak in ctnetlink_create_conntrack()
Published 2024-01-02 · Modified
5.5EPSS 0.003
CVE-2022-0171
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).
Published 2022-08-26 · Modified
5.5EPSS 0.003
CVE-2026-59089
Gimp: gimp: denial of service via integer overflow in playstation tim loader
Published 2026-07-06 · Analyzed
5.5EPSS 0.003
CVE-2024-45778
Grub2: fs/bfs: integer overflow in the bfs parser.
Published 2025-03-03 · Modified
5.5EPSS 0.003
CVE-2024-23301
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Published 2024-01-12 · Modified
5.5EPSS 0.003
CVE-2022-1184
A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service.
Published 2022-08-29 · Modified
5.5EPSS 0.003
CVE-2022-0480
A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.
Published 2022-08-29 · Modified
5.5EPSS 0.003
CVE-2024-8354
Qemu-kvm: usb: assertion failure in usb_ep_get()
Published 2024-09-19 · Modified
5.5EPSS 0.003
CVE-2023-4569
Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c
Published 2023-08-28 · Modified
5.5EPSS 0.003
CVE-2024-1151
Kernel: stack overflow problem in open vswitch kernel module leading to dos
Published 2024-02-11 · Modified
5.5EPSS 0.003
CVE-2023-4194
Kernel: tap: tap_open(): correctly initialize socket uid next fix of i_uid to current_fsuid
Published 2023-08-07 · Modified
5.5EPSS 0.003
CVE-2026-40918
Gimp: gimp: denial of service via crafted pvr image file
Published 2026-04-15 · Analyzed
5.5EPSS 0.003
CVE-2023-4641
Shadow-utils: possible password leak during passwd(1) change
Published 2023-12-27 · Modified
5.5EPSS 0.003
CVE-2024-2496
Libvirt: null pointer dereference in udevconnectlistallinterfaces()
Published 2024-03-18 · Analyzed
5.5EPSS 0.003
CVE-2023-2700
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
Published 2023-05-15 · Modified
5.5EPSS 0.003
CVE-2023-3773
Kernel: xfrm: out-of-bounds read of xfrma_mtimer_thresh nlattr
Published 2023-07-25 · Modified
5.5EPSS 0.003
CVE-2024-0443
Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
Published 2024-01-11 · Modified
5.5EPSS 0.002
← Prev12 / 16Next →