← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
LinuxNetapp
8Fedora
H300s FirmwareH410c Firmware+5 more
Jun 17, 2026
May 2, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
3Angularjs
FedoraprojectNetapp
3Angularjs
FedoraOntap Select Deploy Administration Utility
Jun 17, 2026
May 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PA...Show more
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.Show less
3Fedoraproject
MoodleRedhat
3Enterprise Linux
FedoraMoodle
Jun 17, 2026
Apr 29, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
4Fedoraproject
Podman ProjectPsgo Project+1 more
16Developer Tools
Enterprise LinuxEnterprise Linux Eus+13 more
Jun 17, 2026
Apr 29, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a...Show more
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.Show less
2Fedoraproject
Linux
2Fedora
Linux Kernel
Jun 17, 2026
Apr 29, 2022
N/A· v4
6.6 MEDIUM· v3
4.6 MEDIUM· v2
A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.
3Debian
FedoraprojectSamba
3Cifs Utils
Debian LinuxFedora
Jun 17, 2026
Apr 28, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
4Fedoraproject
NetappOracle+1 more
5Communications Operations Monitor
FedoraManagement Services For Element Software+2 more
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of...Show more
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.Show less
4Fedoraproject
NetappOracle+1 more
5Communications Operations Monitor
FedoraManagement Services For Element Software+2 more
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execu...Show more
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution environment in Redis provides some measures that prevent a script from creating side effects that persist and can affect the execution of the same, or different script, at a later time. Several weaknesses of these measures have been publicly known for a long time, but they had no security impact as the Redis security model did not endorse the concept of users or privileges. With the introduction of ACLs in Redis 6.0, these weaknesses can be exploited by a less privileged users to inject Lua code that will execute at a later time, when a privileged user executes a Lua script. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.Show less
2Chafa Project
Fedoraproject
2Chafa
Fedora
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2...Show more
chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file.Show less
5Debian
FedoraprojectHp+2 more
19Caas Platform
Cifs UtilsDebian Linux+16 more
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
2Fedoraproject
Freerdp
2Fedora
Freerdp
Jun 17, 2026
Apr 26, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an i...Show more
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.Show less
2Fedoraproject
Freerdp
3Extra Packages For Enterprise Linux
FedoraFreerdp
Jun 17, 2026
Apr 26, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue a...Show more
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.Show less
2Fedoraproject
Giflib Project
2Fedora
Giflib
Jun 17, 2026
Apr 25, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
2Fedoraproject
Freetype
2Fedora
Freetype
Jul 9, 2026
Apr 22, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.
2Fedoraproject
Freetype
2Fedora
Freetype
Jul 9, 2026
Apr 22, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
2Fedoraproject
Freetype
2Fedora
Freetype
Jun 17, 2026
Apr 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
3Apple
FedoraprojectVim
3Fedora
MacosVim
Jun 17, 2026
Apr 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
3Debian
FedoraprojectGnome
3Debian Linux
EpiphanyFedora
Jun 17, 2026
Apr 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for...Show more
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.Show less
2Fedoraproject
Golang
3Extra Packages For Enterprise Linux
FedoraGo
Jun 17, 2026
Apr 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
3Fedoraproject
GolangNetapp
3Fedora
GoKubernetes Monitoring Operator
Jun 17, 2026
Apr 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.