VendorsRed Hatenterprise_linux8.0
Vulnerabilities

Red Hat Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1167CVEs
CVE-2026-59087
Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-controlled length into undersized allocation
Published 2026-08-10 · Analyzed
7.8EPSS 0.005
CVE-2019-14815
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
Published 2019-11-25 · Modified
7.8EPSS 0.005
CVE-2019-10166
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
Published 2019-08-02 · Modified
7.8EPSS 0.005
CVE-2023-2491
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Published 2023-05-17 · Modified
7.8EPSS 0.005
CVE-2020-1712
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Published 2020-03-31 · Modified
7.8EPSS 0.005
CVE-2025-26597
Xorg: xwayland: buffer overflow in xkbchangetypesofkey()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2019-18389
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
Published 2019-12-23 · Modified
7.8EPSS 0.004
CVE-2025-5914
Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c
Published 2025-06-09 · Modified
7.8EPSS 0.004
CVE-2025-26595
Xorg: xwayland: buffer overflow in xkbvmodmasktext()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2025-26596
Xorg: xwayland: heap overflow in xkbwritekeysyms()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2019-13313
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
Published 2019-07-05 · Modified
7.8EPSS 0.004
CVE-2023-43787
Libx11: integer overflow in xcreateimage() leading to a heap overflow
Published 2023-10-10 · Modified
7.8EPSS 0.004
CVE-2021-39251
A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-33285
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2026-59091
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
Published 2026-08-10 · Analyzed
7.8EPSS 0.004
CVE-2025-26598
Xorg: xwayland: out-of-bounds write in createpointerbarrierclient()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2025-26599
Xorg: xwayland: use of uninitialized pointer in compredirectwindow()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2022-0135
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
Published 2022-08-25 · Modified
7.8EPSS 0.004
CVE-2022-1158
A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.
Published 2022-08-05 · Modified
7.8EPSS 0.004
CVE-2021-20194
There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.
Published 2021-02-23 · Modified
7.8EPSS 0.004
CVE-2026-40915
Gimp: gimp: heap buffer overflow due to integer overflow in fits image loader
Published 2026-04-15 · Analyzed
7.8EPSS 0.004
CVE-2021-38160
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior
Published 2021-08-07 · Analyzed
7.8EPSS 0.004
CVE-2025-26600
Xorg: xwayland: use-after-free in playreleasedevents()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2025-26601
Xorg: xwayland: use-after-free in syncinittrigger()
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2025-26594
X.org: xwayland: use-after-free of the root cursor
Published 2025-02-25 · Modified
7.8EPSS 0.004
CVE-2024-9675
Buildah: buildah allows arbitrary directory mount
Published 2024-10-09 · Modified
7.8EPSS 0.004
CVE-2021-23177
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
Published 2022-08-23 · Modified
7.8EPSS 0.004
CVE-2021-31566
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.
Published 2022-08-23 · Modified
7.8EPSS 0.004
CVE-2022-0330
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
Published 2022-03-25 · Analyzed
7.8EPSS 0.004
CVE-2026-4775
Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
Published 2026-03-24 · Modified
7.8EPSS 0.004
CVE-2026-66758
Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images
Published 2026-07-27 · Modified
7.8EPSS 0.004
CVE-2024-0409
Xorg-x11-server: selinux context corruption
Published 2024-01-18 · Modified
7.8EPSS 0.004
CVE-2020-25712
A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2020-12-15 · Modified
7.8EPSS 0.004
CVE-2023-3812
Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
Published 2023-07-24 · Modified
7.8EPSS 0.003
CVE-2022-0516
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.
Published 2022-03-08 · Modified
7.8EPSS 0.003
CVE-2022-0358
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.
Published 2022-08-29 · Modified
7.8EPSS 0.003
CVE-2026-58380
Gimp: gimp: stack buffer overflow in pnmscanner_gettoken()
Published 2026-07-06 · Undergoing Analysis
7.8EPSS 0.003
CVE-2021-3717
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.
Published 2022-05-24 · Modified
7.8EPSS 0.003
CVE-2022-2964
A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.
Published 2022-09-09 · Modified
7.8EPSS 0.003
CVE-2024-0646
Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
Published 2024-01-17 · Modified
7.8EPSS 0.003
← Prev7 / 30Next →