VendorsRed Hatenterprise_linux_for_real_time_for_nfv8.0
Vulnerabilities

Red Hat Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
Published 2019-07-17 · Analyzed
7.8KEV4 PoCEPSS 0.522
CVE-2023-5633
Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
Published 2023-10-23 · Modified
7.8EPSS 0.003
CVE-2021-3609
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
Published 2022-03-03 · Modified
7.0EPSS 0.004
CVE-2023-33952
Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects
Published 2023-07-24 · Modified
6.7EPSS 0.005
CVE-2023-33951
Kernel: vmwgfx: race condition leading to information disclosure vulnerability
Published 2023-07-24 · Modified
6.7EPSS 0.003
CVE-2019-11833
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
Published 2019-05-15 · Modified
5.5EPSS 0.006
CVE-2023-3772
Kernel: xfrm: null pointer dereference in xfrm_update_ae_params()
Published 2023-07-25 · Modified
5.5EPSS 0.005
CVE-2021-3659
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.
Published 2022-08-22 · Modified
5.5EPSS 0.003
CVE-2023-4132
Kernel: smsusb: use-after-free caused by do_submit_urb()
Published 2023-08-03 · Modified
5.5EPSS 0.003
CVE-2023-4732
Kernel: race between task migrating pages and another task calling exit_mmap to release those same pages getting invalid opcode bug in include/linux/swapops.h
Published 2023-10-03 · Modified
4.7EPSS 0.002