Redhat Enterprise Linux vulnerabilities
1,853 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158
Vulnerabilities
Page 29 of 93
CVE-2023-50782P3HIGHCVSS 7.5v8.0v9.02024-02-05
CVE-2023-50782 [HIGH] CWE-203 CVE-2023-50782: A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decry
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
nvd
CVE-2021-3445P3HIGHCVSS 7.5v8.02021-05-19
CVE-2021-3445 [HIGH] CWE-347 CVE-2021-3445: A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This fl
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system avail
nvd
CVE-2022-0516P3HIGHCVSS 7.8v8.02022-03-10
CVE-2022-0516 [HIGH] CWE-200 CVE-2022-0516: A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.
nvd
CVE-2022-2964P3HIGHCVSS 7.8v7.0v8.0+1 more2022-09-09
CVE-2022-2964 [HIGH] CWE-119 CVE-2022-2964: A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Et
A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.
nvd
CVE-2020-25647P3HIGHCVSS 7.6v7.0v8.02021-03-03
CVE-2020-25647 [HIGH] CWE-787 CVE-2020-25647: A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors a
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The high
nvd
CVE-2023-5633P3HIGHCVSS 7.8v8.0v9.02023-10-23
CVE-2023-5633 [HIGH] CVE-2023-5633: The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a us
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.
nvd
CVE-2019-2534P3HIGHCVSS 7.1v8.02019-01-16
CVE-2019-2534 [HIGH] CVE-2019-2534: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2026-6384P3HIGHCVSS 7.8v6.0v7.0+2 more2026-04-15
CVE-2026-6384 [HIGH] CWE-120 CVE-2026-6384: A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `R
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.
nvd
CVE-2026-58384P3HIGHCVSS 7.8v9.02026-07-07
CVE-2026-58384 [HIGH] CWE-190 CVE-2026-58384: A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an unders
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
nvd
CVE-2022-3787P3HIGHCVSS 7.8v8.7v9.12023-03-29
CVE-2022-3787 [HIGH] CWE-285 CVE-2022-3787: A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local u
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a
nvd
CVE-2026-48864P3HIGHCVSS 7.8v7.0v8.0+2 more2026-05-26
CVE-2026-48864 [HIGH] CWE-787 CVE-2026-48864: A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-c
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result
nvd
CVE-2026-53000P3HIGHCVSS 7.8v9.0v10.02026-06-24
CVE-2026-53000 [HIGH] CWE-763 CVE-2026-53000: In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu t
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nat: use kfree_rcu to release ops
Florian Westphal says:
"Historically this is not an issue, even for normal base hooks: the data
path doesn't use the original nf_hook_ops that are used to register the
callbacks.
However, in v5.14 I added the ability to dump the active n
nvd
CVE-2008-4302P4MEDIUMCVSS 5.5PoCv5.02008-09-29
CVE-2008-4302 [MEDIUM] CWE-667 CVE-2008-4302: fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a f
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.
nvd
CVE-2026-3260P3HIGHCVSS 7.5v8.0v9.0+1 more2026-03-24
CVE-2026-3260 [HIGH] CWE-770 CVE-2026-3260: A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentiall
nvd
CVE-2021-20254P3MEDIUMCVSS 6.8v7.0v8.02021-05-05
CVE-2021-20254 [MEDIUM] CWE-125 CVE-2021-20254: A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those v
nvd
CVE-2019-0820P3HIGHCVSS 7.5v8.02019-05-16
CVE-2019-0820 [HIGH] CWE-400 CVE-2019-0820: A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
nvd
CVE-2019-17024P3HIGHCVSS 8.8v8.02020-01-08
CVE-2019-17024 [HIGH] CWE-787 CVE-2019-17024: Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of t
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2017-5436P3HIGHCVSS 8.8v6.0v7.02018-06-11
CVE-2017-5436 [HIGH] CWE-787 CVE-2017-5436: An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font.
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-12171P3MEDIUMCVSS 6.5v6.92018-07-26
CVE-2017-12171 [MEDIUM] CWE-284 CVE-2017-12171: A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comme
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.
nvd
CVE-2022-0996P3MEDIUMCVSS 6.5v8.02022-03-23
CVE-2022-0996 [MEDIUM] CWE-287 CVE-2022-0996: A vulnerability was found in the 389 Directory Server that allows expired passwords to access the da
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
nvd