← Back

Redhat

redhat

5,674 CVEs • 537 products

Products (537)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Nov 21, 2024
Apr 13, 2022
N/A· v4
6.3 MEDIUM· v3
3.3 LOW· v2
A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or...Show more
A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak.Show less
1Redhat
1Origin Aggregated Logging
Nov 21, 2024
Apr 11, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was...Show more
A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.Show less
1Redhat
1Openshift
Nov 21, 2024
Apr 11, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.
4Fedoraproject
LinuxNetapp+1 more
15Active Iq Unified Manager
Enterprise LinuxFedora+12 more
Nov 21, 2024
Apr 8, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
3Buildah Project
FedoraprojectRedhat
3Buildah
Enterprise LinuxFedora
Nov 21, 2024
Apr 4, 2022
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux...Show more
A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity.Show less
3Crun Project
FedoraprojectRedhat
4Crun
Enterprise LinuxFedora+1 more
Nov 21, 2024
Apr 4, 2022
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritabl...Show more
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.Show less
3Fedoraproject
Podman ProjectRedhat
14Developer Tools
Enterprise LinuxEnterprise Linux Eus+11 more
Nov 21, 2024
Apr 4, 2022
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheri...Show more
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.Show less
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Apr 1, 2022
N/A· v4
7.1 HIGH· v3
3.3 LOW· v2
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
1Redhat
2Openshift Container Platform
Openshift Machine Config Operator
Nov 21, 2024
Apr 1, 2022
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition c...Show more
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull secrets. There are two scenarios where this data can be accessed. The first is on Baremetal, OpenStack, Ovirt, Vsphere and KubeVirt deployments which do not have a separate internal API endpoint and allow access from outside the cluster to port 22623 from the standard OpenShift API Virtual IP address. The second is on cloud deployments when using unsupported network plugins, which do not create iptables rules that prevent to port 22623. In this scenario, the ignition config is exposed to all pods within the cluster and cannot be accessed externally.Show less
1Redhat
3Business Central
Descision ManagerProcess Automation
Nov 21, 2024
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Nov 21, 2024
Mar 30, 2022
N/A· v4
3.4 LOW· v3
3.6 LOW· v2
A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem
5Canonical
FedoraprojectLinux+2 more
12Enterprise Linux
FedoraH300e Firmware+9 more
Nov 21, 2024
Mar 29, 2022
8.6 HIGH· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47f...Show more
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5Show less
2Netapp
Redhat
2Libvirt
Ontap Select Deploy Administration Utility
Nov 21, 2024
Mar 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop a...Show more
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).Show less
1Redhat
1Kubeclient
Nov 21, 2024
Mar 25, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to ve...Show more
A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).Show less
5Fedoraproject
LinuxNetapp+2 more
30Codeready Linux Builder
Codeready Linux Builder EusCodeready Linux Builder Eus For Power Little Endian+27 more
Nov 21, 2024
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw a...Show more
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.Show less
4Fedoraproject
LinuxNetapp+1 more
383scale Api Management
Codeready Linux BuilderCodeready Linux Builder Eus+35 more
Nov 21, 2024
Mar 25, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their pr...Show more
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.Show less
3Fedoraproject
NetappRedhat
3Fedora
LibvirtOntap Select Deploy Administration Utility
Nov 21, 2024
Mar 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
4Debian
FedoraprojectOpenexr+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Mar 25, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not...Show more
In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of programs linked with OpenEXR.Show less
1Redhat
13scale
Nov 21, 2024
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure...Show more
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.Show less
1Redhat
1Keycloak
Nov 21, 2024
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.