VendorsRed Hathardened_imagesall versions
Vulnerabilities

Red Hat Hardened Images

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2026-5121
Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
Published 2026-03-30 · Modified
9.8EPSS 0.011
CVE-2026-42010
Gnutls: gnutls: authentication bypass via nul character in username
Published 2026-05-07 · Modified
9.8EPSS 0.011
CVE-2026-9256
NGINX ngx_http_rewrite_module vulnerability
Published 2026-05-22 · Modified
9.2EPSS 0.109
CVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
Published 2026-06-17 · Modified
9.2EPSS 0.065
CVE-2026-59851
Libssh: libssh: authentication bypass via missing gssapi principal check
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-0966
Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
Published 2026-03-26 · Modified
8.2EPSS 0.006
CVE-2026-4775
Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
Published 2026-03-24 · Modified
7.8EPSS 0.006
CVE-2026-48864
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
Published 2026-05-26 · Modified
7.8EPSS 0.002
CVE-2026-6846
Binutils: binutils: arbitrary code execution via malformed xcoff object file processing
Published 2026-04-22 · Modified
7.8EPSS 0.002
CVE-2025-14821
Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows
Published 2026-04-07 · Analyzed
7.8EPSS 0.001
CVE-2026-42009
Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
Published 2026-05-18 · Modified
7.5EPSS 0.013
CVE-2026-1584
Gnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binder
Published 2026-04-09 · Modified
7.5EPSS 0.013
CVE-2026-4424
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
Published 2026-03-19 · Modified
7.5EPSS 0.012
CVE-2026-2100
P11-kit: null dereference via c_derivekey with specific null parameters
Published 2026-03-26 · Modified
7.5EPSS 0.012
CVE-2026-6732
Libxml2: libxml2: denial of service via crafted xsd-validated document
Published 2026-04-23 · Analyzed
7.5EPSS 0.006
CVE-2026-59850
Libssh: libssh: use-after-free via data callbacks on closed channels
Published 2026-07-21 · Modified
7.5EPSS 0.003
CVE-2026-59847
Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-59849
Libssh: libssh: denial of service via automatic certificate authentication loop
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-3833
Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
Published 2026-04-30 · Modified
7.4EPSS 0.006
CVE-2026-15370
Libssh: libssh: stack buffer overflow in sftp server longname construction
Published 2026-07-21 · Analyzed
7.3EPSS 0.002
CVE-2026-71226
Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path
Published 2026-08-05 · Modified
7.3EPSS 0.001
CVE-2026-13595
Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
Published 2026-06-29 · Analyzed
6.8EPSS 0.002
CVE-2026-59843
Libssh: libssh: denial of service via zero advertised channel packet size
Published 2026-07-21 · Modified
6.5EPSS 0.006
CVE-2026-59844
Libssh: libssh: denial of service via oversized sftp read length
Published 2026-07-21 · Modified
6.5EPSS 0.006
CVE-2026-9150
Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums
Published 2026-05-20 · Modified
6.5EPSS 0.004
CVE-2026-71225
Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
Published 2026-08-05 · Modified
6.5EPSS 0.003
CVE-2026-9149
Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file
Published 2026-05-20 · Modified
6.5EPSS 0.003
CVE-2026-4426
Libarchive: libarchive: denial of service via malformed iso file processing
Published 2026-03-19 · Modified
6.5EPSS 0.003
CVE-2026-55653
Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
Published 2026-06-23 · Modified
6.5EPSS 0.003
CVE-2026-0964
Libssh: improper sanitation of paths received from scp servers
Published 2026-03-26 · Modified
6.3EPSS 0.004
CVE-2026-13757
P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
Published 2026-06-29 · Modified
6.2EPSS 0.001
CVE-2026-0990
Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing
Published 2026-01-15 · Analyzed
5.9EPSS 0.009
CVE-2026-59845
Libssh: libssh: denial of service via unchecked proxycommand fork() failure
Published 2026-07-21 · Modified
5.9EPSS 0.001
CVE-2026-5704
Tar: tar: hidden file injection via crafted archives
Published 2026-04-06 · Modified
5.5EPSS 0.004
CVE-2026-5745
Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive
Published 2026-04-07 · Modified
5.5EPSS 0.002
CVE-2026-19548
Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing
Published 2026-08-12 · Analyzed
5.5EPSS 0.001
CVE-2026-19617
Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser
Published 2026-08-14 · Analyzed
5.5EPSS 0.001
CVE-2026-6844
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-2625
Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification
Published 2026-04-03 · Analyzed
5.5EPSS 0.001
CVE-2026-3184
Util-linux: util-linux: access control bypass due to improper hostname canonicalization
Published 2026-04-03 · Analyzed
5.3EPSS 0.004
1 / 2Next →