Redhat Enterprise Linux vulnerabilities
1,783 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,783
CISA KEV
22
actively exploited
Public exploits
91
Exploited in wild
26
Severity breakdown
CRITICAL162HIGH609MEDIUM858LOW154
Vulnerabilities
Page 4 of 90
CVE-2026-3634MEDIUMCVSS 6.5v6.0v7.0+3 more2026-03-17
CVE-2026-3634 [MEDIUM] CWE-93 CVE-2026-3634: A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header c
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `soup_message_headers_set_content_type()` function. This vulnerability allows for the injection of arbitrary header-value pairs, potentially leading to HTTP h
nvd
CVE-2026-3441HIGHCVSS 7.1v6.0v7.0+3 more2026-03-16
CVE-2026-3441 [HIGH] CWE-125 CVE-2026-3441: A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an ap
nvd
CVE-2026-3442HIGHCVSS 7.1v6.0v7.0+3 more2026-03-16
CVE-2026-3442 [HIGH] CWE-125 CVE-2026-3442: A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the
nvd
CVE-2026-3099HIGHCVSS 7.3v6.0v7.0+3 more2026-03-12
CVE-2026-3099 [HIGH] CWE-323 CVE-2026-3099: A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDom
A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a single valid authentication header and replay it repeatedly. Consequently, the
nvd
CVE-2026-3497MEDIUMCVSS 6.9v8.0v9.0+1 more2026-03-12
CVE-2026-3497 [MEDIUM] CWE-908 CVE-2026-3497: Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerabilit
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAP
nvd
CVE-2025-12801MEDIUMCVSS 6.5v6.0v7.0+3 more2026-03-04
CVE-2025-12801 [MEDIUM] CWE-279 CVE-2025-12801: A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux,
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, a
nvd
CVE-2025-9572MEDIUMCVSS 6.5v9.02026-02-27
CVE-2025-9572 [MEDIUM] CWE-863 CVE-2025-9572: n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
nvd
CVE-2026-26103HIGHCVSS 7.1v10.02026-02-25
CVE-2026-26103 [HIGH] CWE-862 CVE-2026-26103: A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for res
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys an
nvd
CVE-2026-26104MEDIUMCVSS 5.5v10.02026-02-25
CVE-2026-26104 [MEDIUM] CWE-862 CVE-2026-26104: A flaw was found in the udisks storage management daemon that allows unprivileged users to back up L
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to at
nvd
CVE-2026-2443MEDIUMCVSS 5.3v6.0v7.0+3 more2026-02-13
CVE-2026-2443 [MEDIUM] CWE-125 CVE-2026-2443: A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires
nvd
CVE-2026-1709CRITICALCVSS 9.8v9.0v10.02026-02-06
CVE-2026-1709 [CRITICAL] CWE-322 CVE-2026-1709: A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-si
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TP
nvd
CVE-2026-1801MEDIUMCVSS 6.5v6.0v7.0+3 more2026-02-03
CVE-2026-1801 [MEDIUM] CWE-444 CVE-2026-1801: A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerabilit
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attac
nvd
CVE-2026-1536MEDIUMCVSS 5.3v6.0v7.0+3 more2026-01-28
CVE-2026-1536 [MEDIUM] CWE-93 CVE-2026-1536: A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition heade
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to
nvd
CVE-2026-1539MEDIUMCVSS 5.8v6.0v7.0+3 more2026-01-28
CVE-2026-1539 [MEDIUM] CWE-201 CVE-2026-1539: A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be s
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the Proxy-Authorization header if the request is redirected to a different host. As a result, sensitive proxy credentials may be l
nvd
CVE-2026-1467MEDIUMCVSS 5.3v6.0v7.0+3 more2026-01-27
CVE-2026-1467 [MEDIUM] CWE-93 CVE-2026-1467: A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Ret
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allo
nvd
CVE-2025-14512MEDIUMCVSS 6.5v7.0v8.0+2 more2025-12-11
CVE-2025-14512 [MEDIUM] CWE-190 CVE-2025-14512: A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (Do
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
nvd
CVE-2025-14087CRITICALCVSS 9.8v7.0v8.0+2 more2025-12-10
CVE-2025-14087 [CRITICAL] CWE-190 CVE-2025-14087: A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corr
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
nvd
CVE-2025-9784HIGHCVSS 7.5v8.0v9.02025-09-02
CVE-2025-9784 [HIGH] CWE-770 CVE-2025-9784: A flaw was found in Undertow where malformed client requests can trigger server-side stream resets w
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implem
nvd
CVE-2025-8283LOWCVSS 3.7v8.0v9.0+1 more2025-07-28
CVE-2025-8283 [LOW] CWE-15 CVE-2025-8283: A vulnerability was found in the netavark package, a network stack for containers used with Podman.
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's
nvd
CVE-2025-7519MEDIUMCVSS 6.7v6.0v7.0+3 more2025-07-14
CVE-2025-7519 [MEDIUM] CWE-787 CVE-2025-7519: A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth,
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy f
nvd