Redhat Enterprise Linux vulnerabilities
1,738 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,738
CISA KEV
20
actively exploited
Public exploits
88
Exploited in wild
26
Severity breakdown
CRITICAL157HIGH589MEDIUM839LOW153
Vulnerabilities
Page 20 of 87
CVE-2022-0485MEDIUMCVSS 4.8v8.02022-08-29
CVE-2022-0485 [MEDIUM] CWE-252 CVE-2022-0485: A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies usin
A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.
nvd
CVE-2022-0480MEDIUMCVSS 5.5v9.02022-08-29
CVE-2022-0480 [MEDIUM] CWE-770 CVE-2022-0480: A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lea
A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.
nvd
CVE-2022-0851MEDIUMCVSS 5.5v7.0v8.02022-08-29
CVE-2022-0851 [MEDIUM] CWE-200 CVE-2022-0851: There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the acti
There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the activation key via the process command line via e.g. htop or ps. The specific impact varies upon the
nvd
CVE-2022-1198MEDIUMCVSS 5.5v9.02022-08-29
CVE-2022-1198 [MEDIUM] CWE-416 CVE-2022-1198: A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows
A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space.
nvd
CVE-2022-1016MEDIUMCVSS 5.5v8.0v9.02022-08-29
CVE-2022-1016 [MEDIUM] CWE-824 CVE-2022-1016: A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.
nvd
CVE-2021-3864HIGHCVSS 7.0v6.0v7.0+1 more2022-08-26
CVE-2021-3864 [HIGH] CWE-284 CVE-2021-3864: A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries execute
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern i
nvd
CVE-2021-35939MEDIUMCVSS 6.7v8.02022-08-26
CVE-2021-35939 [MEDIUM] CVE-2021-35939: It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only imp
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integ
nvd
CVE-2022-34301MEDIUMCVSS 6.7v7.0v8.0+1 more2022-08-26
CVE-2022-34301 [MEDIUM] CVE-2022-34301: A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bo
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Pa
nvd
CVE-2022-0175MEDIUMCVSS 5.5v8.02022-08-26
CVE-2022-0175 [MEDIUM] CWE-909 CVE-2022-0175: A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly in
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
nvd
CVE-2022-0168MEDIUMCVSS 4.4v8.0v9.02022-08-26
CVE-2022-0168 [MEDIUM] CWE-476 CVE-2022-0168: A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in th
A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the system.
nvd
CVE-2022-34303MEDIUMCVSS 6.7v7.0v8.0+1 more2022-08-26
CVE-2022-34303 [MEDIUM] CVE-2022-34303: A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to b
A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is re
nvd
CVE-2022-34302MEDIUMCVSS 6.7v7.0v8.0+1 more2022-08-26
CVE-2022-34302 [MEDIUM] CVE-2022-34302: A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this boot
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Part
nvd
CVE-2021-3669MEDIUMCVSS 5.5v6.0v7.0+1 more2022-08-26
CVE-2021-3669 [MEDIUM] CWE-400 CVE-2021-3669: A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
nvd
CVE-2022-0171MEDIUMCVSS 5.5v8.0v9.02022-08-26
CVE-2022-0171 [MEDIUM] CWE-459 CVE-2022-0171: A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).
nvd
CVE-2022-0135HIGHCVSS 7.8v8.02022-08-25
CVE-2022-0135 [HIGH] CWE-787 CVE-2022-0135: An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This fl
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
nvd
CVE-2021-35937MEDIUMCVSS 6.4v6.0v7.0+2 more2022-08-25
CVE-2021-35937 [MEDIUM] CVE-2021-35937: A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to by
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2021-35938MEDIUMCVSS 6.7v7.0v8.0+1 more2022-08-25
CVE-2021-35938 [MEDIUM] CWE-59 CVE-2021-35938: A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credenti
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data
nvd
CVE-2021-4204HIGHCVSS 7.1v9.02022-08-24
CVE-2021-4204 [HIGH] CWE-20 CVE-2021-4204: An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper In
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.
nvd
CVE-2021-4213HIGHCVSS 7.5v8.02022-08-24
CVE-2021-4213 [HIGH] CWE-401 CVE-2021-4213: A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
nvd
CVE-2021-4159MEDIUMCVSS 4.4v8.02022-08-24
CVE-2021-4159 [MEDIUM] CWE-202 CVE-2021-4159: A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
nvd