Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 74 of 94
CVE-2005-0384P4MEDIUMCVSS 5.0v2.12005-03-15
CVE-2005-0384 [MEDIUM] CVE-2005-0384: Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to caus
Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.
nvd
CVE-2013-2561P4MEDIUMCVSS 6.3v6.02013-11-23
CVE-2013-2561 [MEDIUM] CWE-59 CVE-2013-2561: OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
nvd
CVE-2026-3832P4LOWCVSS 3.7v6.0v7.0+3 more2026-04-30
CVE-2026-3832 [LOW] CWE-179 CVE-2026-3832: A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a speci
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, p
nvd
CVE-2007-6285P4MEDIUMCVSS 6.2v4.0v5.02007-12-20
CVE-2007-6285 [MEDIUM] CWE-16 CVE-2007-6285: The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterp
The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/m
nvd
CVE-2011-3593P4MEDIUMCVSS 5.7v6.02013-06-08
CVE-2011-3593 [MEDIUM] CWE-399 CVE-2011-3593: A certain Red Hat patch to the vlan_hwaccel_do_receive function in net/8021q/vlan_core.c in the Linu
A certain Red Hat patch to the vlan_hwaccel_do_receive function in net/8021q/vlan_core.c in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows remote attackers to cause a denial of service (system crash) via priority-tagged VLAN frames.
nvd
CVE-2019-7150P4MEDIUMCVSS 5.5v8.02019-01-29
CVE-2019-7150 [MEDIUM] CWE-125 CVE-2019-7150: An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlat
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.
nvd
CVE-2021-3605P4MEDIUMCVSS 5.5v8.02021-08-25
CVE-2021-3605 [MEDIUM] CWE-119 CVE-2021-3605: There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who
There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
nvd
CVE-2013-1935P4MEDIUMCVSS 5.7v6.02013-07-16
CVE-2013-1935 [MEDIUM] CWE-362 CVE-2013-1935: A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32-358.11.1.el6 on Red
A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly implement the PV EOI feature, which allows guest OS users to cause a denial of service (host OS crash) by leveraging a time window during which interrupts are disabled but copy_to_user function calls are
nvd
CVE-2018-10882P4MEDIUMCVSS 5.5v7.02018-07-27
CVE-2018-10882 [MEDIUM] CWE-787 CVE-2018-10882: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
nvd
CVE-2021-30470P4MEDIUMCVSS 5.5v7.02021-05-26
CVE-2021-30470 [MEDIUM] CWE-674 CVE-2021-30470: A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), Pd
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.
nvd
CVE-2014-0055P4MEDIUMCVSS 5.5v6.02014-03-26
CVE-2014-0055 [MEDIUM] CVE-2014-0055: The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel packa
The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhost_get_vq_desc errors, which allows guest OS users to cause a denial of service (host OS crash) via unspecified vectors.
nvd
CVE-2021-4115P4MEDIUMCVSS 5.5v8.02022-02-21
CVE-2021-4115 [MEDIUM] CWE-400 CVE-2021-4115: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to proc
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
nvd
CVE-2022-25309P4MEDIUMCVSS 5.5v8.0v9.02022-09-06
CVE-2022-25309 [MEDIUM] CWE-122 CVE-2022-25309: A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_t
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial of service.
nvd
CVE-2020-11669P4MEDIUMCVSS 5.5v7.02020-04-10
CVE-2020-11669 [MEDIUM] CVE-2020-11669: An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/
An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMOR, aka CID-53a712bae5dd.
nvd
CVE-2020-14373P4MEDIUMCVSS 5.5v7.0v8.02020-09-03
CVE-2020-14373 [MEDIUM] CWE-416 CVE-2020-14373: A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attac
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.
nvd
CVE-2024-3567P4MEDIUMCVSS 5.5v9.02024-04-10
CVE-2024-3567 [MEDIUM] CWE-617 CVE-2024-3567: A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.
nvd
CVE-2022-1263P4MEDIUMCVSS 5.5v8.0v9.02022-08-31
CVE-2022-1263 [MEDIUM] CWE-476 CVE-2022-1263: A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enab
A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.
nvd
CVE-2017-15128P4MEDIUMCVSS 5.5v7.02018-01-14
CVE-2017-15128 [MEDIUM] CWE-119 CVE-2017-15128: A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG).
nvd
CVE-2023-1981P4MEDIUMCVSS 5.5v6.0v7.0+2 more2023-05-26
CVE-2023-1981 [MEDIUM] CWE-400 CVE-2023-1981: A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
nvd
CVE-2013-4287P4MEDIUMCVSS 4.3v6.02013-10-17
CVE-2013-4287 [MEDIUM] CWE-310 CVE-2013-4287: Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large a
nvd