← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectPuma
3Debian Linux
FedoraPuma
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Pum...Show more
Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may disagree on where a request starts and ends. This would allow requests to be smuggled via the front-end proxy to Puma. The vulnerability has been fixed in 5.6.4 and 4.3.12. Users are advised to upgrade as soon as possible. Workaround: when deploying a proxy in front of Puma, turning on any and all functionality to make sure that the request matches the RFC7230 standard.Show less
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
4Debian
FedoraprojectOracle+1 more
4Communications Cloud Native Core Network Exposure Function
Debian LinuxFedora+1 more
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
3Debian
FedoraprojectMediawiki
3Debian Linux
FedoraMediawiki
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Specia...Show more
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.Show less
3Debian
FedoraprojectUclouvain
3Debian Linux
FedoraOpenjpeg
Jun 17, 2026
Mar 29, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory,...Show more
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.Show less
5Canonical
FedoraprojectLinux+2 more
12Enterprise Linux
FedoraH300e Firmware+9 more
Jun 17, 2026
Mar 29, 2022
8.6 HIGH· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47f...Show more
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5Show less
2Fedoraproject
Libarchive
2Fedora
Libarchive
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
2Fedoraproject
Python
2Fedora
Pillow
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
2Fedoraproject
Gnu
2Fedora
Gcc
Jun 17, 2026
Mar 26, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
3Fedoraproject
NetatalkWesterndigital
13Fedora
My Cloud Dl2100 FirmwareMy Cloud Dl4100 Firmware+10 more
Jun 17, 2026
Mar 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
2Fedoraproject
Kiwix
2Fedora
Libkiwix
Jun 17, 2026
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.
3Fedoraproject
LinuxNetapp
13Fedora
H300e FirmwareH300s Firmware+10 more
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged a...Show more
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.Show less
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
3Fedoraproject
LinuxNetapp
10Fedora
H300e FirmwareH300s Firmware+7 more
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to cras...Show more
A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.Show less
5Fedoraproject
LinuxNetapp+2 more
30Codeready Linux Builder
Codeready Linux Builder EusCodeready Linux Builder Eus For Power Little Endian+27 more
Jun 17, 2026
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw a...Show more
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.Show less
4Fedoraproject
LinuxNetapp+1 more
383scale Api Management
Codeready Linux BuilderCodeready Linux Builder Eus+35 more
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their pr...Show more
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.Show less