Redhat

Hardened Images

116 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 21.07.2026 11:08:30
  • Zuletzt bearbeitet 22.09.2026 19:47:55

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote ...

  • EPSS 0.16%
  • Veröffentlicht 21.07.2026 09:16:53
  • Zuletzt bearbeitet 22.09.2026 19:47:33

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long nam...

  • EPSS 0.2%
  • Veröffentlicht 10.07.2026 09:55:49
  • Zuletzt bearbeitet 22.09.2026 00:16:31

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata spa...

  • EPSS 0.47%
  • Veröffentlicht 30.06.2026 07:16:32
  • Zuletzt bearbeitet 02.10.2026 03:16:40

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of ano...

  • EPSS 0.15%
  • Veröffentlicht 29.06.2026 18:44:24
  • Zuletzt bearbeitet 29.09.2026 01:16:45

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRA...

  • EPSS 0.11%
  • Veröffentlicht 29.06.2026 08:06:09
  • Zuletzt bearbeitet 31.08.2026 18:17:13

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent par...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 23.06.2026 03:37:00
  • Zuletzt bearbeitet 24.09.2026 23:17:11

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators...

  • EPSS 0.09%
  • Veröffentlicht 23.06.2026 03:36:25
  • Zuletzt bearbeitet 07.10.2026 03:16:59

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 03:36:22
  • Zuletzt bearbeitet 07.10.2026 03:16:59

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when...

  • EPSS 0.29%
  • Veröffentlicht 19.06.2026 16:28:33
  • Zuletzt bearbeitet 06.10.2026 03:17:05

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured numb...