Redhat Enterprise Linux vulnerabilities
1,783 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,783
CISA KEV
22
actively exploited
Public exploits
91
Exploited in wild
26
Severity breakdown
CRITICAL162HIGH609MEDIUM858LOW154
Vulnerabilities
Page 17 of 90
CVE-2023-3640HIGHCVSS 7.8v8.0v9.02023-07-24
CVE-2023-3640 [HIGH] CVE-2023-3640: A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the ini
nvd
CVE-2023-3750MEDIUMCVSS 5.3v9.02023-07-24
CVE-2023-3750 [MEDIUM] CWE-667 CVE-2023-3750: A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool
A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.
nvd
CVE-2023-3019MEDIUMCVSS 6.5v8.0v9.02023-07-24
CVE-2023-3019 [MEDIUM] CWE-416 CVE-2023-3019: A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
nvd
CVE-2023-33952MEDIUMCVSS 6.7v8.0v9.02023-07-24
CVE-2023-33952 [MEDIUM] CWE-415 CVE-2023-33952: A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local privileged user to escalate privileges and execute code in the context of th
nvd
CVE-2023-33951MEDIUMCVSS 5.3v8.0v9.02023-07-24
CVE-2023-33951 [MEDIUM] CWE-413 CVE-2023-33951: A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists w
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
nvd
CVE-2023-34966HIGHCVSS 7.5v8.0v9.02023-07-20
CVE-2023-34966 [HIGH] CWE-835 CVE-2023-34966: An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing S
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked
nvd
CVE-2023-34967MEDIUMCVSS 5.3v8.0v9.02023-07-20
CVE-2023-34967 [MEDIUM] CWE-843 CVE-2023-34967: A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing S
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of type checking in callers of the dal
nvd
CVE-2022-2127MEDIUMCVSS 5.9v6.0v7.0+2 more2023-07-20
CVE-2022-2127 [MEDIUM] CWE-125 CVE-2022-2127: An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd
An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM auth
nvd
CVE-2023-34968MEDIUMCVSS 5.3v8.0v9.02023-07-20
CVE-2023-34968 [MEDIUM] CWE-201 CVE-2023-34968: A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba disclos
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
nvd
CVE-2023-3347MEDIUMCVSS 5.9v8.0v9.02023-07-20
CVE-2023-3347 [MEDIUM] CWE-347 CVE-2023-3347: A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not e
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the net
nvd
CVE-2023-38252MEDIUMCVSS 5.5v6.02023-07-14
CVE-2023-38252 [MEDIUM] CWE-125 CVE-2023-38252: An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may al
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
nvd
CVE-2023-38253MEDIUMCVSS 5.5v6.02023-07-14
CVE-2023-38253 [MEDIUM] CWE-125 CVE-2023-38253: An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue m
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
nvd
CVE-2023-3618MEDIUMCVSS 6.5v8.0v9.02023-07-12
CVE-2023-3618 [MEDIUM] CWE-120 CVE-2023-3618: A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
nvd
CVE-2023-3354HIGHCVSS 7.5v7.0v8.0+1 more2023-07-11
CVE-2023-3354 [HIGH] CWE-476 CVE-2023-3354: A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU che
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL poi
nvd
CVE-2023-3269HIGHCVSS 7.8PoCv6.0v7.0+2 more2023-07-11
CVE-2023-3269 [HIGH] CWE-416 CVE-2023-3269: A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for
A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges.
nvd
CVE-2023-1672MEDIUMCVSS 5.3v8.0v9.02023-07-11
CVE-2023-1672 [MEDIUM] CWE-362 CVE-2023-1672: A race condition exists in the Tang server functionality for key generation and key rotation. This f
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
nvd
CVE-2023-34432HIGHCVSS 7.8v6.0v7.02023-07-10
CVE-2023-34432 [HIGH] CWE-122 CVE-2023-34432: A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/format
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
nvd
CVE-2023-34318HIGHCVSS 7.8v6.0v7.02023-07-10
CVE-2023-34318 [HIGH] CWE-122 CVE-2023-34318: A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:1
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
nvd
CVE-2023-32627MEDIUMCVSS 5.5v6.0v7.02023-07-10
CVE-2023-32627 [MEDIUM] CWE-1077 CVE-2023-32627: A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/v
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
nvd
CVE-2023-1183MEDIUMCVSS 5.5v8.0v9.02023-07-10
CVE-2023-1183 [MEDIUM] CWE-20 CVE-2023-1183: A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/scr
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
nvd