VendorsRed Hatenterprise_linux9.0
Vulnerabilities

Red Hat Enterprise Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

601CVEs
CVE-2024-5742
Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file
Published 2024-06-12 · Modified
6.7EPSS 0.003
CVE-2024-45777
Grub2: grub-core/gettext: integer overflow leads to heap oob write.
Published 2025-02-19 · Modified
6.7EPSS 0.002
CVE-2023-2194
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.
Published 2023-04-20 · Modified
6.7EPSS 0.002
CVE-2023-2513
A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors.
Published 2023-05-08 · Modified
6.7EPSS 0.002
CVE-2023-6917
Pcp: unsafe use of directories allows pcp to root privilege escalation
Published 2024-02-28 · Modified
6.7EPSS 0.002
CVE-2025-9908
Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams
Published 2026-02-27 · Analyzed
6.7EPSS 0.002
CVE-2025-7519
Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write
Published 2025-07-14 · Analyzed
6.7EPSS 0.002
CVE-2025-9909
Aap-gateway: improper path validation in gateway allows credential exfiltration
Published 2026-02-27 · Analyzed
6.7EPSS 0.002
CVE-2025-9907
Event-driven-ansible: event stream test mode exposes sensitive headers in aap eda
Published 2026-02-27 · Analyzed
6.7EPSS 0.002
CVE-2026-5164
Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request
Published 2026-03-30 · Analyzed
6.7EPSS 0.002
CVE-2023-40660
Opensc: potential pin bypass when card tracks its own login state
Published 2023-11-06 · Modified
6.6EPSS 0.009
CVE-2023-1073
A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Published 2023-03-27 · Modified
6.6EPSS 0.004
CVE-2025-5918
Libarchive: reading past eof may be triggered for piped file streams
Published 2025-06-09 · Analyzed
6.6EPSS 0.004
CVE-2024-0607
Kernel: nf_tables: pointer math issue in nft_byteorder_eval()
Published 2024-01-18 · Modified
6.6EPSS 0.002
CVE-2025-5915
Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c
Published 2025-06-09 · Modified
6.6EPSS 0.002
CVE-2026-73433
Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write
Published 2026-08-12 · Undergoing Analysis
6.6EPSS 0.001
CVE-2026-73583
Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr
Published 2026-08-13 · Analyzed
6.6EPSS 0.001
CVE-2022-40982
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Published 2023-08-11 · Modified
6.5EPSS 0.030
CVE-2023-3255
Qemu: vnc: infinite loop in inflate_buffer() leads to denial of service
Published 2023-09-13 · Modified
6.5EPSS 0.019
CVE-2023-0056
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Published 2023-03-23 · Modified
6.5EPSS 0.018
CVE-2023-6277
Libtiff: out-of-memory in tiffopen via a craft file
Published 2023-11-24 · Modified
6.5EPSS 0.018
CVE-2023-42669
Samba: "rpcecho" development server allows denial of service via sleep() call on ad dc
Published 2023-11-06 · Modified
6.5EPSS 0.017
CVE-2023-4527
Glibc: stack read overflow in getaddrinfo in no-aaaa mode
Published 2023-09-18 · Modified
6.5EPSS 0.017
CVE-2023-40745
Libtiff: integer overflow in tiffcp.c
Published 2023-10-05 · Modified
6.5EPSS 0.014
CVE-2024-9676
Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)
Published 2024-10-15 · Modified
6.5EPSS 0.013
CVE-2023-1667
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
Published 2023-05-26 · Modified
6.5EPSS 0.013
CVE-2022-2850
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
Published 2022-10-14 · Modified
6.5EPSS 0.013
CVE-2022-1706
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Published 2022-05-17 · Modified
6.5EPSS 0.013
CVE-2023-41175
Libtiff: potential integer overflow in raw2tiff.c
Published 2023-10-05 · Modified
6.5EPSS 0.013
CVE-2023-1729
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
Published 2023-05-15 · Analyzed
6.5EPSS 0.013
CVE-2023-6683
Qemu: vnc: null pointer dereference in qemu_clipboard_request()
Published 2024-01-12 · Analyzed
6.5EPSS 0.013
CVE-2023-3618
Segmentation fault in fax3encode in libtiff/tif_fax3.c
Published 2023-07-12 · Modified
6.5EPSS 0.012
CVE-2023-52160
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.
Published 2024-02-22 · Modified
6.5EPSS 0.012
CVE-2022-24808
net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference
Published 2024-04-16 · Analyzed
6.5EPSS 0.011
CVE-2022-24809
net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference
Published 2024-04-16 · Analyzed
6.5EPSS 0.011
CVE-2023-1192
Use-after-free in smb2_is_status_io_timeout()
Published 2023-11-01 · Modified
6.5EPSS 0.011
CVE-2023-2283
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,` which is initialized to SSH_ERROR and later rewritten to save the return value of the function call `pki_key_check_hash_compatible.` The value of the variable is not changed between this point and the cryptographic verification. Therefore any error between them calls `goto error` returning SSH_OK.
Published 2023-05-26 · Modified
6.5EPSS 0.011
CVE-2022-24806
net-snmp vulnerable to Improper Input Validation when SETing malformed OIDs in master agent and subagent simultaneously
Published 2024-04-16 · Analyzed
6.5EPSS 0.011
CVE-2022-24807
net-snmp: A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access
Published 2024-04-16 · Analyzed
6.5EPSS 0.010
CVE-2023-6240
Kernel: marvin vulnerability side-channel leakage in the rsa decryption operation
Published 2024-02-04 · Modified
6.5EPSS 0.010
← Prev8 / 16Next →