VendorsRed Hatenterprise_linux8.0
Vulnerabilities

Red Hat Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1167CVEs
CVE-2022-0487
A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.
Published 2022-02-04 · Modified
5.5EPSS 0.004
CVE-2022-3821
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Published 2022-11-08 · Modified
5.5EPSS 0.004
CVE-2023-42754
Kernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()
Published 2023-10-05 · Modified
5.5EPSS 0.004
CVE-2021-3505
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.
Published 2021-04-19 · Modified
5.5EPSS 0.004
CVE-2026-5704
Tar: tar: hidden file injection via crafted archives
Published 2026-04-06 · Modified
5.5EPSS 0.004
CVE-2023-6228
Libtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.c
Published 2023-12-18 · Modified
5.5EPSS 0.004
CVE-2023-40550
Shim: out-of-bound read in verify_buffer_sbat()
Published 2024-01-29 · Modified
5.5EPSS 0.004
CVE-2019-18811
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
Published 2019-11-07 · Modified
5.5EPSS 0.004
CVE-2021-3620
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
Published 2022-03-03 · Modified
5.5EPSS 0.004
CVE-2023-1981
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
Published 2023-05-26 · Modified
5.5EPSS 0.004
CVE-2020-25641
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Published 2020-10-06 · Modified
5.5EPSS 0.004
CVE-2024-0232
Sqlite: use-after-free bug in jsonparseaddnodearray
Published 2024-01-16 · Modified
5.5EPSS 0.004
CVE-2021-3527
A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not bounded, a malicious guest could use this flaw to influence the array length and cause the QEMU process to perform an excessive allocation on the stack, resulting in a denial of service.
Published 2021-05-26 · Modified
5.5EPSS 0.004
CVE-2022-0852
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ps. The specific impact varies upon the privileges of the Red Hat account in question, but it could affect the integrity, availability, and/or data confidentiality of other systems that are administered by that account. This occurs regardless of how the password is supplied to convert2rhel.
Published 2022-08-29 · Modified
5.5EPSS 0.004
CVE-2023-43788
Libxpm: out of bounds read in xpmcreatexpmimagefrombuffer()
Published 2023-10-10 · Modified
5.5EPSS 0.004
CVE-2019-18391
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
Published 2019-12-23 · Modified
5.5EPSS 0.004
CVE-2022-2905
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.
Published 2022-09-09 · Modified
5.5EPSS 0.004
CVE-2023-43789
Libxpm: out of bounds read on xpm with corrupted colormap
Published 2023-10-12 · Modified
5.5EPSS 0.004
CVE-2023-3576
Libtiff: memory leak in tiffcrop.c
Published 2023-10-04 · Modified
5.5EPSS 0.003
CVE-2026-3632
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
Published 2026-03-17 · Analyzed
5.5EPSS 0.003
CVE-2026-6695
Gimp: gimp: remote code execution via crafted paa file
Published 2026-08-03 · Analyzed
5.5EPSS 0.003
CVE-2023-4042
Ghostscript: incomplete fix for cve-2020-16305
Published 2023-08-23 · Modified
5.5EPSS 0.003
CVE-2026-59088
Gimp: gimp: denial of service via signed integer overflow in fli file processing
Published 2026-08-10 · Analyzed
5.5EPSS 0.003
CVE-2021-3602
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).
Published 2022-03-03 · Modified
5.5EPSS 0.003
CVE-2022-0175
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
Published 2022-08-26 · Modified
5.5EPSS 0.003
CVE-2023-6622
Kernel: null pointer dereference vulnerability in nft_dynset_init()
Published 2023-12-08 · Analyzed
5.5EPSS 0.003
CVE-2024-0408
Xorg-x11-server: selinux unlabeled glx pbuffer
Published 2024-01-18 · Modified
5.5EPSS 0.003
CVE-2023-3164
Heap-buffer-overflow in extractimagesection()
Published 2023-11-02 · Modified
5.5EPSS 0.003
CVE-2020-14391
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
Published 2021-02-08 · Modified
5.5EPSS 0.003
CVE-2022-0851
There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the activation key via the process command line via e.g. htop or ps. The specific impact varies upon the subscription, but generally this would allow an attacker to register systems purchased by the victim until discovered; a form of fraud. This could occur regardless of how the activation key is supplied to convert2rhel because it involves how convert2rhel provides it to subscription-manager.
Published 2022-08-29 · Modified
5.5EPSS 0.003
CVE-2022-2873
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.
Published 2022-08-22 · Modified
5.5EPSS 0.003
CVE-2024-1062
389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
Published 2024-02-12 · Modified
5.5EPSS 0.003
CVE-2022-1852
A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.
Published 2022-06-30 · Modified
5.5EPSS 0.003
CVE-2024-0690
Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
Published 2024-02-06 · Modified
5.5EPSS 0.003
CVE-2023-7192
Kernel: refcount leak in ctnetlink_create_conntrack()
Published 2024-01-02 · Modified
5.5EPSS 0.003
CVE-2022-0171
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).
Published 2022-08-26 · Modified
5.5EPSS 0.003
CVE-2026-59089
Gimp: gimp: denial of service via integer overflow in playstation tim loader
Published 2026-07-06 · Analyzed
5.5EPSS 0.003
CVE-2024-45778
Grub2: fs/bfs: integer overflow in the bfs parser.
Published 2025-03-03 · Modified
5.5EPSS 0.003
CVE-2021-3669
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
Published 2022-08-26 · Modified
5.5EPSS 0.003
CVE-2024-23301
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Published 2024-01-12 · Modified
5.5EPSS 0.003
← Prev22 / 30Next →