VendorsRed Hatenterprise_linuxall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2269CVEs
CVE-2021-20245
A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Published 2021-03-09 · Modified
7.1EPSS 0.012
CVE-2021-20244
A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Published 2021-03-09 · Modified
7.1EPSS 0.012
CVE-2023-3758
Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published 2024-04-18 · Modified
7.1EPSS 0.010
CVE-2021-3746
A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by specially-crafted TPM2 command packets that then trigger the issue when the state of the TPM2's volatile state is written. The highest threat from this vulnerability is to system availability. This issue affects libtpms versions before 0.8.5, before 0.7.9 and before 0.6.6.
Published 2021-10-19 · Modified
7.1EPSS 0.010
CVE-2023-6291
Keycloak: redirect_uri validation bypass
Published 2024-01-26 · Modified
7.1EPSS 0.010
CVE-2022-3775
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.
Published 2022-12-19 · Modified
7.1EPSS 0.009
CVE-2026-1933
Samba: missing access check on reparse point operations
Published 2026-05-27 · Modified
7.1EPSS 0.009
CVE-2024-7341
Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters
Published 2024-09-09 · Modified
7.1EPSS 0.008
CVE-2026-4887
Gimp: gimp:memory disclosure and denial of service via specially crafted pcx image
Published 2026-03-26 · Modified
7.1EPSS 0.005
CVE-2023-6606
Kernel: out-of-bounds read vulnerability in smbcalcsize
Published 2023-12-08 · Modified
7.1EPSS 0.005
CVE-2023-2422
Keycloak: oauth client impersonation
Published 2023-10-04 · Modified
7.1EPSS 0.005
CVE-2011-3632
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
Published 2019-11-26 · Modified
7.1EPSS 0.005
CVE-2023-6610
Kernel: oob access in smb2_dump_detail
Published 2023-12-08 · Modified
7.1EPSS 0.004
CVE-2023-4156
Heap out of bound read in builtin.c
Published 2023-09-25 · Modified
7.1EPSS 0.004
CVE-2023-3567
Kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race
Published 2023-07-24 · Modified
7.1EPSS 0.004
CVE-2022-1353
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
Published 2022-04-29 · Modified
7.1EPSS 0.004
CVE-2023-5366
Openvswitch don't match packets on nd_target field
Published 2023-10-06 · Modified
7.1EPSS 0.004
CVE-2021-3501
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
Published 2021-05-05 · Modified
7.1EPSS 0.004
CVE-2019-14822
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
Published 2019-11-25 · Modified
7.1EPSS 0.004
CVE-2016-2150
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
Published 2016-06-09 · Modified
7.1EPSS 0.004
CVE-2022-2990
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Published 2022-09-13 · Modified
7.1EPSS 0.003
CVE-2019-18390
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
Published 2019-12-23 · Modified
7.1EPSS 0.003
CVE-2022-2989
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Published 2022-09-13 · Modified
7.1EPSS 0.003
CVE-2026-66759
Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images
Published 2026-07-27 · Analyzed
7.1EPSS 0.003
CVE-2023-2977
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.
Published 2023-06-01 · Modified
7.1EPSS 0.003
CVE-2023-1652
A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.
Published 2023-03-29 · Modified
7.1EPSS 0.002
CVE-2023-4387
Kernel: vmxnet3: use-after-free in vmxnet3_rq_alloc_rx_buf()
Published 2023-08-16 · Modified
7.1EPSS 0.002
CVE-2024-0775
Kernel: use-after-free while changing the mount option in __ext4_remount leading
Published 2024-01-22 · Modified
7.1EPSS 0.002
CVE-2026-40917
Gimp: gimp: application crashes or information disclosure via crafted icns image files
Published 2026-04-15 · Analyzed
7.1EPSS 0.002
CVE-2026-3441
Binutils: gnu binutils: information disclosure via specially crafted xcoff object file
Published 2026-03-15 · Modified
7.1EPSS 0.002
CVE-2026-3442
Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linker
Published 2026-03-15 · Modified
7.1EPSS 0.002
CVE-2026-13601
Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
Published 2026-06-29 · Modified
7.1EPSS 0.002
CVE-2026-5673
Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing
Published 2026-04-06 · Analyzed
7.1EPSS 0.002
CVE-2026-68743
Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1
Published 2026-08-04 · Analyzed
7.1EPSS 0.001
CVE-2026-26103
Udisks: missing authorization check allows unprivileged users to restore luks headers via udisks d-bus api
Published 2026-02-25 · Modified
7.1EPSS 0.001
CVE-2018-14879
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
Published 2019-10-03 · Modified
7.0EPSS 0.047
CVE-2019-3842
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".
Published 2019-04-09 · Modified
7.01 PoCEPSS 0.012
CVE-2025-2784
Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content
Published 2025-04-03 · Modified
7.0EPSS 0.008
CVE-2021-20271
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Published 2021-03-26 · Modified
7.0EPSS 0.008
CVE-2021-3864
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.
Published 2022-08-26 · Modified
7.0EPSS 0.008
← Prev25 / 57Next →