Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 75 of 94
CVE-2026-40919P4MEDIUMCVSS 5.5v6.0v7.0+2 more2026-04-15
CVE-2026-40919 [MEDIUM] CWE-787 CVE-2026-40919: A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plug
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potentially impacting the stability of the GIMP application
nvd
CVE-2023-38469P4MEDIUMCVSS 5.5v8.0v9.02023-11-02
CVE-2023-38469 [MEDIUM] CWE-617 CVE-2023-38469: A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_re
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
nvd
CVE-2021-3669P4MEDIUMCVSS 5.5v6.0v7.0+1 more2022-08-26
CVE-2021-3669 [MEDIUM] CWE-400 CVE-2021-3669: A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
nvd
CVE-2012-6136P4MEDIUMCVSS 5.5v6.02019-11-20
CVE-2012-6136 [MEDIUM] CWE-276 CVE-2012-6136: tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitra
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
nvd
CVE-2021-3659P4MEDIUMCVSS 5.5v7.0v8.02022-08-22
CVE-2021-3659 [MEDIUM] CWE-252 CVE-2021-3659: A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking su
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-20297P4MEDIUMCVSS 5.5v8.02021-05-26
CVE-2021-20297 [MEDIUM] CWE-20 CVE-2021-20297: A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a pr
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
nvd
CVE-2024-2496P4MEDIUMCVSS 5.5v6.0v7.0+2 more2024-03-18
CVE-2024-2496 [MEDIUM] CWE-476 CVE-2024-2496: A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt.
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.
nvd
CVE-2023-4459P4MEDIUMCVSS 5.5v8.0v9.02023-08-21
CVE-2023-4459 [MEDIUM] CWE-476 CVE-2023-4459: A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c
A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause a denial of service due to a missing sanity check during cleanup.
nvd
CVE-2023-5090P4MEDIUMCVSS 5.5v8.0v9.02023-11-06
CVE-2023-5090 [MEDIUM] CWE-755 CVE-2023-5090: A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct acc
A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
nvd
CVE-2022-3707P4MEDIUMCVSS 5.5v8.0v9.02023-03-06
CVE-2022-3707 [MEDIUM] CWE-460 CVE-2022-3707: A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VG
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.
nvd
CVE-2026-40916P4MEDIUMCVSS 5.5v6.0v7.0+2 more2026-04-15
CVE-2026-40916 [MEDIUM] CWE-787 CVE-2026-40916: A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decod
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.
nvd
CVE-2023-3161P4MEDIUMCVSS 5.5v8.0v9.02023-06-12
CVE-2023-3161 [MEDIUM] CWE-1335 CVE-2023-3161: A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
nvd
CVE-2024-0639P4MEDIUMCVSS 5.5v8.0v9.02024-01-17
CVE-2024-0639 [MEDIUM] CWE-833 CVE-2024-0639: A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/s
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system.
nvd
CVE-2024-0641P4MEDIUMCVSS 5.5v8.0v9.02024-01-17
CVE-2024-0641 [MEDIUM] CWE-833 CVE-2024-0641: A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Li
A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system.
nvd
CVE-2026-6844P4MEDIUMCVSS 5.5v7.0v8.0+2 more2026-04-22
CVE-2026-6844 [MEDIUM] CWE-400 CVE-2026-6844: A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit tw
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-
nvd
CVE-2013-0281P4MEDIUMCVSS 4.3v6.02013-11-23
CVE-2013-0281 [MEDIUM] CWE-399 CVE-2013-0281: Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).
nvd
CVE-2004-0957P4MEDIUMCVSS 6.8v3.02005-02-09
CVE-2004-0957 [MEDIUM] CVE-2004-0957: Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
nvd
CVE-2013-0383P4MEDIUMCVSS 4.3v6.02013-01-17
CVE-2013-0383 [MEDIUM] CVE-2013-0383: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote attackers to affect availability via unknown vectors related to Server Locking.
nvd
CVE-2013-1855P4MEDIUMCVSS 4.3v6.02013-03-19
CVE-2013-1855 [MEDIUM] CWE-79 CVE-2013-1855: The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted
nvd
CVE-2020-15719P4MEDIUMCVSS 4.2v8.02020-07-14
CVE-2020-15719 [MEDIUM] CWE-295 CVE-2020-15719: libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-pa
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
nvd