VendorsRed Hatenterprise_linux8.0
Vulnerabilities

Red Hat Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1167CVEs
CVE-2019-19319
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, aka CID-345c0dbf3a30.
Published 2019-11-27 · Modified
6.5EPSS 0.007
CVE-2023-43785
Libx11: out-of-bounds memory access in _xkbreadkeysyms()
Published 2023-10-10 · Modified
6.5EPSS 0.006
CVE-2024-0564
Kernel: max page sharing of kernel samepage merging (ksm) may cause memory deduplication
Published 2024-01-30 · Modified
6.5EPSS 0.006
CVE-2023-39329
Openjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c
Published 2024-07-13 · Modified
6.5EPSS 0.006
CVE-2026-9150
Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums
Published 2026-05-20 · Modified
6.5EPSS 0.006
CVE-2025-14512
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Published 2025-12-11 · Modified
6.5EPSS 0.006
CVE-2025-5351
Libssh: double free vulnerability in libssh key export functions
Published 2025-07-04 · Modified
6.5EPSS 0.006
CVE-2023-5455
Ipa: invalid csrf protection
Published 2024-01-10 · Modified
6.5EPSS 0.006
CVE-2026-9149
Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file
Published 2026-05-20 · Modified
6.5EPSS 0.006
CVE-2021-3948
An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.
Published 2022-02-18 · Modified
6.5EPSS 0.006
CVE-2026-4426
Libarchive: libarchive: denial of service via malformed iso file processing
Published 2026-03-19 · Modified
6.5EPSS 0.006
CVE-2021-3979
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
Published 2022-08-25 · Modified
6.5EPSS 0.006
CVE-2026-71225
Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
Published 2026-08-05 · Modified
6.5EPSS 0.005
CVE-2020-10756
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
Published 2020-07-09 · Modified
6.5EPSS 0.005
CVE-2026-55653
Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
Published 2026-06-23 · Modified
6.5EPSS 0.005
CVE-2026-2239
Gimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflow
Published 2026-03-26 · Analyzed
6.5EPSS 0.005
CVE-2025-47712
Nbd: nbdkit: integer overflow triggers an assertion resulting in denial of service
Published 2025-06-09 · Modified
6.5EPSS 0.005
CVE-2025-12801
Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
Published 2026-03-04 · Modified
6.5EPSS 0.005
CVE-2021-3611
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.
Published 2022-05-11 · Modified
6.5EPSS 0.005
CVE-2025-47711
Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service
Published 2025-06-09 · Modified
6.5EPSS 0.005
CVE-2026-5142
Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass
Published 2026-07-01 · Analyzed
6.5EPSS 0.004
CVE-2026-5135
Foreman: foreman: unauthorized modification of host configurations via broken access control
Published 2026-07-01 · Analyzed
6.5EPSS 0.004
CVE-2026-73196
Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding
Published 2026-08-20 · Analyzed
6.5EPSS 0.004
CVE-2026-1801
Libsoup: libsoup: http request smuggling via malformed chunk headers
Published 2026-02-03 · Analyzed
6.5EPSS 0.004
CVE-2026-11820
Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string
Published 2026-06-23 · Analyzed
6.5EPSS 0.004
CVE-2023-42755
Kernel: rsvp: out-of-bounds read in rsvp_classify()
Published 2023-10-05 · Modified
6.5EPSS 0.004
CVE-2026-66339
Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels
Published 2026-07-24 · Analyzed
6.5EPSS 0.004
CVE-2021-4145
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
Published 2022-01-25 · Modified
6.5EPSS 0.004
CVE-2026-66337
Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until()
Published 2026-07-24 · Analyzed
6.5EPSS 0.004
CVE-2026-3633
Libsoup: libsoup: header and http request injection via crlf injection
Published 2026-03-17 · Analyzed
6.5EPSS 0.004
CVE-2021-20257
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Published 2022-03-16 · Modified
6.5EPSS 0.004
CVE-2020-10690
There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition as the process wakes up to terminate and clean all attached files. The system crashes due to the cdev structure being invalid (as already freed) which is pointed to by the inode.
Published 2020-05-08 · Modified
6.5EPSS 0.004
CVE-2021-3930
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
Published 2022-02-18 · Modified
6.5EPSS 0.003
CVE-2024-49393
Mutt: neomutt: to and cc email header fields are not protected by cryptographic signing
Published 2024-11-12 · Modified
6.5EPSS 0.003
CVE-2023-3019
Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()
Published 2023-07-24 · Modified
6.5EPSS 0.003
CVE-2019-19339
It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel CPUs handle inconsistency between, virtual to physical memory address translations in CPU's local cache and system software's Paging structure entries. A privileged guest user may use this flaw to induce a hardware Machine Check Error on the host processor, resulting in a severe DoS scenario by halting the processor. System software like OS OR Virtual Machine Monitor (VMM) use virtual memory system for storing program instructions and data in memory. Virtual Memory system uses Paging structures like Page Tables and Page Directories to manage system memory. The processor's Memory Management Unit (MMU) uses Paging structure entries to translate program's virtual memory addresses to physical memory addresses. The processor stores these address translations into its local cache buffer called - Translation Lookaside Buffer (TLB). TLB has two parts, one for instructions and other for data addresses. System software can modify its Paging structure entries to change address mappings OR certain attributes like page size etc. Upon such Paging structure alterations in memory, system software must invalidate the corresponding address translations in the processor's TLB cache. But before this TLB invalidation takes place, a privileged guest user may trigger an instruction fetch operation, which could use an already cached, but now invalid, virtual to physical address translation from Instruction TLB (ITLB). Thus accessing an invalid physical memory address and resulting in halting the processor due to the Machine Check Error (MCE) on Page Size Change.
Published 2020-01-17 · Modified
6.5EPSS 0.003
CVE-2019-12067
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.
Published 2021-06-02 · Modified
6.5EPSS 0.003
CVE-2026-3634
Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
Published 2026-03-17 · Analyzed
6.5EPSS 0.003
CVE-2021-3941
In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of programs linked with OpenEXR.
Published 2022-03-25 · Modified
6.5EPSS 0.003
CVE-2022-4144
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.
Published 2022-11-29 · Modified
6.5EPSS 0.003
← Prev17 / 30Next →