Redhat

Hardened Images

114 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 22.09.2026 12:52:02
  • Zuletzt bearbeitet 22.09.2026 19:37:36

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or appli...

  • EPSS 0.12%
  • Veröffentlicht 22.09.2026 08:35:18
  • Zuletzt bearbeitet 22.09.2026 15:17:25

Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.

  • EPSS 0.11%
  • Veröffentlicht 18.09.2026 14:13:53
  • Zuletzt bearbeitet 18.09.2026 19:06:08

A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an exces...

  • EPSS 0.44%
  • Veröffentlicht 15.09.2026 17:58:51
  • Zuletzt bearbeitet 16.09.2026 19:42:43

A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds r...

  • EPSS 0.21%
  • Veröffentlicht 15.09.2026 15:08:33
  • Zuletzt bearbeitet 21.09.2026 12:17:21

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands,...

  • EPSS 0.12%
  • Veröffentlicht 11.09.2026 17:41:36
  • Zuletzt bearbeitet 07.10.2026 18:17:19

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `S...

  • EPSS 0.12%
  • Veröffentlicht 10.09.2026 08:57:03
  • Zuletzt bearbeitet 02.10.2026 14:17:11

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mo...

  • EPSS 0.12%
  • Veröffentlicht 10.09.2026 08:40:36
  • Zuletzt bearbeitet 25.09.2026 23:16:54

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are ...

  • EPSS 0.39%
  • Veröffentlicht 09.09.2026 16:12:07
  • Zuletzt bearbeitet 21.09.2026 12:17:22

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurati...

  • EPSS 0.32%
  • Veröffentlicht 09.09.2026 16:06:27
  • Zuletzt bearbeitet 12.09.2026 00:17:06

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-suppli...