← Back

Enterprise Linux Eus

enterprise_linux_eus

Vendor: Redhat • 779 CVEs

CVEs (779)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
DebianFedoraproject+3 more
37Bootstrap Os
Codeready Linux BuilderCodeready Linux Builder For Power Little Endian+34 more
Jun 3, 2026
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to esca...Show more
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.Show less
3Linux
NetappRedhat
323scale Api Management
Build Of QuarkusCodeready Linux Builder Eus+29 more
Nov 21, 2024
Mar 3, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in ne...Show more
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.Show less
6Canonical
DebianFedoraproject+3 more
23Codeready Linux Builder
Debian LinuxDiskstation Manager+20 more
Apr 23, 2025
Feb 21, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4...Show more
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.Show less
5Canonical
DebianFedoraproject+2 more
17Debian Linux
Enterprise LinuxEnterprise Linux Desktop+14 more
Nov 21, 2024
Feb 18, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictl...Show more
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.Show less
5Canonical
DebianFedoraproject+2 more
25Codeready Linux Builder
Debian LinuxEnterprise Linux+22 more
Nov 21, 2024
Feb 18, 2022
N/A· v4
8.1 HIGH· v3
8.5 HIGH· v2
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
5Canonical
DebianFedoraproject+2 more
24Codeready Linux Builder
Debian LinuxEnterprise Linux+21 more
Nov 21, 2024
Feb 18, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
4Dogtagpki
FedoraprojectOracle+1 more
12Dogtagpki
Enterprise LinuxEnterprise Linux Eus+9 more
Nov 21, 2024
Feb 16, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin p...Show more
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.Show less
7Canonical
OraclePolkit Project+4 more
30Command Center
Enterprise LinuxEnterprise Linux Desktop+27 more
Nov 6, 2025
Jan 28, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic...Show more
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.Show less
2Fedoraproject
Redhat
8Enterprise Linux
Enterprise Linux EusEnterprise Linux Server Aus+5 more
Nov 3, 2025
Dec 23, 2021
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially c...Show more
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.Show less
6C Ares Project
FedoraprojectNodejs+3 more
17C Ares
Enterprise LinuxEnterprise Linux Computer Node+14 more
Nov 21, 2024
Nov 23, 2021
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The h...Show more
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.Show less
11Apache
BroadcomDebian+8 more
39Brocade Fabric Operating System Firmware
Cloud BackupClustered Data Ontap+36 more
Oct 27, 2025
Sep 16, 2021
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
4Debian
FedoraprojectLinuxptp Project+1 more
7Debian Linux
Enterprise LinuxEnterprise Linux Aus+4 more
Nov 21, 2024
Jul 9, 2021
N/A· v4
8.8 HIGH· v3
8.0 HIGH· v2
A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code e...Show more
A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1.Show less
2Netapp
Redhat
13Codeready Linux Builder
Enterprise LinuxEnterprise Linux Eus+10 more
Nov 21, 2024
May 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to acces...Show more
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.Show less
5Canonical
DebianOpensuse+2 more
10Debian Linux
Enterprise LinuxEnterprise Linux Aus+7 more
Nov 21, 2024
Oct 7, 2020
N/A· v4
6.6 MEDIUM· v3
6.5 MEDIUM· v2
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws....Show more
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.Show less
3Fedoraproject
MicrosoftRedhat
6Asp.net Core
Enterprise LinuxEnterprise Linux Aus+3 more
Feb 23, 2026
Sep 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker...Show more
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>Show less
7Apache
CanonicalDebian+4 more
25Communications Element Manager
Communications Session Report ManagerCommunications Session Route Manager+22 more
Nov 21, 2024
Aug 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.Show less
4Canonical
GnuOpensuse+1 more
7Enterprise Linux
Enterprise Linux EusEnterprise Linux Server Aus+4 more
Nov 21, 2024
Jul 31, 2020
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized m...Show more
There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.Show less
4Canonical
GnuOpensuse+1 more
7Enterprise Linux
Enterprise Linux EusEnterprise Linux Server Aus+4 more
Nov 21, 2024
Jul 31, 2020
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to re...Show more
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.Show less
5Debian
NodejsOpensuse+2 more
7Communications Cloud Native Core Network Function Cloud Native Environment
Debian LinuxEnterprise Linux+4 more
Nov 21, 2024
Feb 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
6Debian
FedoraprojectNodejs+3 more
13Debian Linux
Enterprise LinuxEnterprise Linux Desktop+10 more
Nov 21, 2024
Feb 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed