VendorsRed Hatenterprise_linuxall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2269CVEs
CVE-2012-5644
libuser has information disclosure when moving user's home directory
Published 2019-11-25 · Analyzed
5.5EPSS 0.004
CVE-2023-42754
Kernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()
Published 2023-10-05 · Modified
5.5EPSS 0.004
CVE-2015-7837
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
Published 2017-09-19 · Modified
5.5EPSS 0.004
CVE-2021-3505
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.
Published 2021-04-19 · Modified
5.5EPSS 0.004
CVE-2026-5704
Tar: tar: hidden file injection via crafted archives
Published 2026-04-06 · Modified
5.5EPSS 0.004
CVE-2023-6228
Libtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.c
Published 2023-12-18 · Modified
5.5EPSS 0.004
CVE-2017-15121
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
Published 2017-12-06 · Modified
5.5EPSS 0.004
CVE-2023-40550
Shim: out-of-bound read in verify_buffer_sbat()
Published 2024-01-29 · Modified
5.5EPSS 0.004
CVE-2019-18811
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
Published 2019-11-07 · Modified
5.5EPSS 0.004
CVE-2006-4342
The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a denial of service (deadlock) by running the shmat function on an shm at the same time that shmctl is removing that shm (IPC_RMID), which prevents a spinlock from being unlocked.
Published 2006-10-17 · Modified
5.5EPSS 0.004
CVE-2021-3620
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
Published 2022-03-03 · Modified
5.5EPSS 0.004
CVE-2023-1981
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
Published 2023-05-26 · Modified
5.5EPSS 0.004
CVE-2014-5118
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
Published 2019-11-18 · Modified
5.5EPSS 0.004
CVE-2020-25641
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Published 2020-10-06 · Modified
5.5EPSS 0.004
CVE-2014-8171
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
Published 2018-02-09 · Modified
5.5EPSS 0.004
CVE-2024-0232
Sqlite: use-after-free bug in jsonparseaddnodearray
Published 2024-01-16 · Modified
5.5EPSS 0.004
CVE-2017-15127
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG).
Published 2018-01-14 · Modified
5.5EPSS 0.004
CVE-2017-15116
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
Published 2017-11-30 · Modified
5.5EPSS 0.004
CVE-2017-12167
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.
Published 2018-07-26 · Modified
5.5EPSS 0.004
CVE-2021-3527
A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not bounded, a malicious guest could use this flaw to influence the array length and cause the QEMU process to perform an excessive allocation on the stack, resulting in a denial of service.
Published 2021-05-26 · Modified
5.5EPSS 0.004
CVE-2022-0852
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ps. The specific impact varies upon the privileges of the Red Hat account in question, but it could affect the integrity, availability, and/or data confidentiality of other systems that are administered by that account. This occurs regardless of how the password is supplied to convert2rhel.
Published 2022-08-29 · Modified
5.5EPSS 0.004
CVE-2023-43788
Libxpm: out of bounds read in xpmcreatexpmimagefrombuffer()
Published 2023-10-10 · Modified
5.5EPSS 0.004
CVE-2011-3637
The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.
Published 2012-05-17 · Modified
5.5EPSS 0.004
CVE-2019-18391
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
Published 2019-12-23 · Modified
5.5EPSS 0.004
CVE-2023-38252
W3m: out of bounds read in strnew_size() at w3m/str.c
Published 2023-07-14 · Modified
5.5EPSS 0.004
CVE-2023-38253
W3m: out of bounds read in growbuf_to_str() at w3m/indep.c
Published 2023-07-14 · Modified
5.5EPSS 0.004
CVE-2014-8181
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
Published 2019-11-06 · Modified
5.5EPSS 0.004
CVE-2022-2905
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.
Published 2022-09-09 · Modified
5.5EPSS 0.004
CVE-2023-43789
Libxpm: out of bounds read on xpm with corrupted colormap
Published 2023-10-12 · Modified
5.5EPSS 0.004
CVE-2018-10894
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
Published 2018-08-01 · Modified
5.5EPSS 0.004
CVE-2026-3632
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
Published 2026-03-17 · Analyzed
5.5EPSS 0.003
CVE-2023-3576
Libtiff: memory leak in tiffcrop.c
Published 2023-10-04 · Modified
5.5EPSS 0.003
CVE-2026-6695
Gimp: gimp: remote code execution via crafted paa file
Published 2026-08-03 · Analyzed
5.5EPSS 0.003
CVE-2023-4042
Ghostscript: incomplete fix for cve-2020-16305
Published 2023-08-23 · Modified
5.5EPSS 0.003
CVE-2026-59088
Gimp: gimp: denial of service via signed integer overflow in fli file processing
Published 2026-08-10 · Analyzed
5.5EPSS 0.003
CVE-2021-3602
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).
Published 2022-03-03 · Modified
5.5EPSS 0.003
CVE-2022-0175
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
Published 2022-08-26 · Modified
5.5EPSS 0.003
CVE-2024-0408
Xorg-x11-server: selinux unlabeled glx pbuffer
Published 2024-01-18 · Modified
5.5EPSS 0.003
CVE-2023-6622
Kernel: null pointer dereference vulnerability in nft_dynset_init()
Published 2023-12-08 · Analyzed
5.5EPSS 0.003
CVE-2019-10140
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
Published 2019-08-15 · Modified
5.5EPSS 0.003
← Prev40 / 57Next →