Redhat

Hardened Images

82 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 21.07.2026 13:18:18
  • Zuletzt bearbeitet 17.08.2026 22:17:15

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

  • EPSS 0.12%
  • Veröffentlicht 21.07.2026 13:17:18
  • Zuletzt bearbeitet 19.08.2026 05:17:04

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

  • EPSS 0.99%
  • Veröffentlicht 21.07.2026 13:17:16
  • Zuletzt bearbeitet 22.07.2026 19:16:57

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-...

  • EPSS 0.53%
  • Veröffentlicht 21.07.2026 11:32:16
  • Zuletzt bearbeitet 17.08.2026 22:17:15

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

  • EPSS 0.11%
  • Veröffentlicht 21.07.2026 11:26:43
  • Zuletzt bearbeitet 17.08.2026 22:17:15

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

  • EPSS 0.53%
  • Veröffentlicht 21.07.2026 11:16:12
  • Zuletzt bearbeitet 17.08.2026 22:17:15

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

  • EPSS 0.42%
  • Veröffentlicht 21.07.2026 11:08:30
  • Zuletzt bearbeitet 19.08.2026 05:17:04

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote ...

  • EPSS 0.16%
  • Veröffentlicht 21.07.2026 09:16:53
  • Zuletzt bearbeitet 17.08.2026 22:16:59

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long nam...

  • EPSS 0.2%
  • Veröffentlicht 10.07.2026 09:55:49
  • Zuletzt bearbeitet 19.08.2026 11:16:46

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata spa...

  • EPSS 0.47%
  • Veröffentlicht 30.06.2026 07:16:32
  • Zuletzt bearbeitet 19.08.2026 18:16:32

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of ano...