VendorsRed Hatenterprise_linuxall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2269CVEs
CVE-2020-1712
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Published 2020-03-31 · Modified
7.8EPSS 0.005
CVE-2011-1145
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
Published 2019-11-14 · Modified
7.8EPSS 0.005
CVE-2013-1943
The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privileges or obtain sensitive information from kernel memory via a crafted application, related to arch/x86/kvm/paging_tmpl.h and virt/kvm/kvm_main.c.
Published 2013-07-16 · Modified
7.8EPSS 0.004
CVE-2025-5914
Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c
Published 2025-06-09 · Modified
7.8EPSS 0.004
CVE-2025-26597
Xorg: xwayland: buffer overflow in xkbchangetypesofkey()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2019-18389
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
Published 2019-12-23 · Modified
7.8EPSS 0.004
CVE-2025-26596
Xorg: xwayland: heap overflow in xkbwritekeysyms()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2025-26595
Xorg: xwayland: buffer overflow in xkbvmodmasktext()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2019-13313
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
Published 2019-07-05 · Modified
7.8EPSS 0.004
CVE-2013-4251
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
Published 2019-11-04 · Modified
7.8EPSS 0.004
CVE-2017-15104
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
Published 2017-12-18 · Modified
7.8EPSS 0.004
CVE-2023-43787
Libx11: integer overflow in xcreateimage() leading to a heap overflow
Published 2023-10-10 · Modified
7.8EPSS 0.004
CVE-2016-8657
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privileges when jboss service is started, stopped, or restarted.
Published 2018-07-31 · Modified
7.8EPSS 0.004
CVE-2021-39251
A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-33285
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2010-4661
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
Published 2019-11-13 · Modified
7.8EPSS 0.004
CVE-2026-59091
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
Published 2026-08-10 · Analyzed
7.8EPSS 0.004
CVE-2025-26598
Xorg: xwayland: out-of-bounds write in createpointerbarrierclient()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2025-26599
Xorg: xwayland: use of uninitialized pointer in compredirectwindow()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2022-0135
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
Published 2022-08-25 · Modified
7.8EPSS 0.004
CVE-2022-1158
A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.
Published 2022-08-05 · Modified
7.8EPSS 0.004
CVE-2021-20194
There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.
Published 2021-02-23 · Modified
7.8EPSS 0.004
CVE-2026-40915
Gimp: gimp: heap buffer overflow due to integer overflow in fits image loader
Published 2026-04-15 · Analyzed
7.8EPSS 0.004
CVE-2021-38160
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior
Published 2021-08-07 · Analyzed
7.8EPSS 0.004
CVE-2025-26600
Xorg: xwayland: use-after-free in playreleasedevents()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2025-26601
Xorg: xwayland: use-after-free in syncinittrigger()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2025-26594
X.org: xwayland: use-after-free of the root cursor
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2024-9675
Buildah: buildah allows arbitrary directory mount
Published 2024-10-09 · Modified
7.8EPSS 0.004
CVE-2023-34432
Heap-buffer-overflow in src/formats_i.c
Published 2023-07-10 · Modified
7.8EPSS 0.004
CVE-2021-23177
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
Published 2022-08-23 · Modified
7.8EPSS 0.004
CVE-2021-31566
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.
Published 2022-08-23 · Modified
7.8EPSS 0.004
CVE-2022-0330
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
Published 2022-03-25 · Analyzed
7.8EPSS 0.004
CVE-2026-4775
Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
Published 2026-03-24 · Modified
7.8EPSS 0.004
CVE-2017-1000111
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW.
Published 2017-10-04 · Modified
7.8EPSS 0.004
CVE-2023-30549
Unpatched extfs vulnerabilities are exploitable through suid-mode Apptainer
Published 2023-04-25 · Modified
7.8EPSS 0.004
CVE-2016-2568
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
Published 2017-02-13 · Modified
7.8EPSS 0.004
CVE-2026-66758
Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images
Published 2026-07-27 · Modified
7.8EPSS 0.004
CVE-2022-3715
A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.
Published 2023-01-05 · Modified
7.8EPSS 0.004
CVE-2024-0409
Xorg-x11-server: selinux context corruption
Published 2024-01-18 · Modified
7.8EPSS 0.004
CVE-2020-25712
A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2020-12-15 · Modified
7.8EPSS 0.004
← Prev14 / 57Next →