← Back

Redhat

redhat

5,899 CVEs • 544 products

Products (544)

Click to collapse
Toggle
Satellite
satellite
Linux
linux
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Quay
quay
Storage
storage
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,899)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Redhat
Xmlsoft
20Enterprise Linux
Enterprise Linux EusEnterprise Linux For Arm 64+17 more
Sep 18, 2026
Jun 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when...Show more
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.Show less
2Libarchive
Redhat
3Enterprise Linux
LibarchiveOpenshift Container Platform
Sep 1, 2026
Jun 9, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can le...Show more
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.Show less
2Libarchive
Redhat
3Enterprise Linux
LibarchiveOpenshift Container Platform
Sep 1, 2026
Jun 9, 2025
N/A· v4
5.0 MEDIUM· v3
N/A· v2
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seeming...Show more
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.Show less
2Libarchive
Redhat
3Enterprise Linux
LibarchiveOpenshift Container Platform
Sep 1, 2026
Jun 9, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content by...Show more
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.Show less
2Libarchive
Redhat
3Enterprise Linux
LibarchiveOpenshift Container Platform
Sep 1, 2026
Jun 9, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This mean...Show more
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.Show less
2Libarchive
Redhat
3Enterprise Linux
LibarchiveOpenshift Container Platform
Sep 9, 2026
Jun 9, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condit...Show more
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.Show less
2Nbdkit Project
Redhat
3Enterprise Linux
Enterprise Linux Advanced VirtualizationNbdkit
Jun 30, 2026
Jun 9, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even large...Show more
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.Show less
1Redhat
1Hibernate Validator
Jun 17, 2026
Jun 3, 2025
6.9 MEDIUM· v4
7.3 HIGH· v3
N/A· v2
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access...Show more
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.Show less
5Debian
LinuxOracle+2 more
6Debian Linux
Enterprise LinuxLinux+3 more
Sep 1, 2026
May 30, 2025
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attack...Show more
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.Show less
2Redhat
Stackrox
2Advanced Cluster Security
Stackrox
Jun 17, 2026
May 27, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the nam...Show more
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or through a compromised third-party product.Show less
2Freerdp
Redhat
2Enterprise Linux
Freerdp
Jun 30, 2026
May 16, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial o...Show more
A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.Show less
1Redhat
1Pagure
Jun 17, 2026
May 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
1Redhat
1Pagure
Jun 17, 2026
May 12, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git re...Show more
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.Show less
1Redhat
1Quay
Aug 7, 2026
May 6, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
1Redhat
1Build Of Keycloak
Jun 17, 2026
Apr 29, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
3Apache
DebianRedhat
3Debian Linux
Enterprise LinuxHttp Server
Jun 29, 2026
Apr 29, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is...Show more
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.Show less
2Fig2dev Project
Redhat
2Enterprise Linux
Fig2dev
Jun 30, 2026
Apr 23, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.
2Fig2dev Project
Redhat
2Enterprise Linux
Fig2dev
Jun 30, 2026
Apr 23, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.
2Fig2dev Project
Redhat
2Enterprise Linux
Fig2dev
Jun 30, 2026
Apr 23, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.
2Fig2dev Project
Redhat
2Enterprise Linux
Fig2dev
Jun 30, 2026
Apr 23, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.