Redhat

Hardened Images

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 06.04.2026 15:17:27
  • Zuletzt bearbeitet 22.04.2026 20:08:59

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allo...

  • EPSS 0.09%
  • Veröffentlicht 03.04.2026 18:43:45
  • Zuletzt bearbeitet 01.05.2026 19:29:51

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a s...

  • EPSS 0.01%
  • Veröffentlicht 03.04.2026 18:38:09
  • Zuletzt bearbeitet 01.05.2026 21:00:31

A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP...

  • EPSS 0.09%
  • Veröffentlicht 30.03.2026 08:16:18
  • Zuletzt bearbeitet 14.05.2026 23:16:37

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buff...

  • EPSS 0.05%
  • Veröffentlicht 26.03.2026 20:06:28
  • Zuletzt bearbeitet 11.05.2026 17:16:11

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface)...

  • EPSS 0.02%
  • Veröffentlicht 26.03.2026 20:06:28
  • Zuletzt bearbeitet 30.04.2026 16:43:18

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them unde...

  • EPSS 0.05%
  • Veröffentlicht 26.03.2026 20:01:46
  • Zuletzt bearbeitet 25.04.2026 02:16:01

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attemp...

  • EPSS 0.05%
  • Veröffentlicht 24.03.2026 14:42:47
  • Zuletzt bearbeitet 11.05.2026 22:22:14

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write du...

  • EPSS 0.16%
  • Veröffentlicht 19.03.2026 13:53:39
  • Zuletzt bearbeitet 03.05.2026 21:16:11

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by suppl...

  • EPSS 0.36%
  • Veröffentlicht 19.03.2026 13:50:27
  • Zuletzt bearbeitet 14.05.2026 23:16:37

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can expl...