Redhat

Hardened Images

114 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 09.09.2026 08:34:35
  • Zuletzt bearbeitet 22.09.2026 23:17:07

A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens befor...

Medienbericht
  • EPSS 1.03%
  • Veröffentlicht 02.09.2026 15:13:02
  • Zuletzt bearbeitet 03.09.2026 18:12:56

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are no...

  • EPSS 1.2%
  • Veröffentlicht 02.09.2026 15:12:58
  • Zuletzt bearbeitet 03.09.2026 18:12:56

A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or conti...

  • EPSS 0.12%
  • Veröffentlicht 02.09.2026 15:11:47
  • Zuletzt bearbeitet 03.09.2026 18:12:56

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newl...

Medienbericht
  • EPSS 0.1%
  • Veröffentlicht 02.09.2026 15:05:34
  • Zuletzt bearbeitet 04.09.2026 19:17:27

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mo...

Medienbericht
  • EPSS 0.11%
  • Veröffentlicht 02.09.2026 15:05:33
  • Zuletzt bearbeitet 05.09.2026 14:17:23

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credential...

Medienbericht
  • EPSS 0.13%
  • Veröffentlicht 01.09.2026 14:53:45
  • Zuletzt bearbeitet 02.10.2026 14:17:11

A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction....

  • EPSS 0.13%
  • Veröffentlicht 31.08.2026 19:23:18
  • Zuletzt bearbeitet 29.09.2026 21:17:19

A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes t...

  • EPSS 0.11%
  • Veröffentlicht 28.08.2026 14:21:04
  • Zuletzt bearbeitet 28.08.2026 20:20:21

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's c...

  • EPSS 0.14%
  • Veröffentlicht 24.08.2026 16:12:38
  • Zuletzt bearbeitet 28.08.2026 21:17:10

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802....