Redhat

Openshift Container Platform

335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 16:20:17
  • Zuletzt bearbeitet 21.08.2026 16:18:22

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mou...

  • EPSS 0.26%
  • Veröffentlicht 11.08.2026 15:34:06
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an...

  • EPSS 0.28%
  • Veröffentlicht 11.08.2026 11:23:59
  • Zuletzt bearbeitet 24.08.2026 07:16:52

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflecti...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 11:23:55
  • Zuletzt bearbeitet 24.08.2026 07:16:53

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egre...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 05.08.2026 12:42:10
  • Zuletzt bearbeitet 19.08.2026 21:17:36

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-t...

  • EPSS 0.13%
  • Veröffentlicht 05.08.2026 12:37:17
  • Zuletzt bearbeitet 24.08.2026 12:16:54

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 05.08.2026 12:16:52
  • Zuletzt bearbeitet 19.08.2026 21:17:35

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for ...

  • EPSS 0.13%
  • Veröffentlicht 04.08.2026 18:37:21
  • Zuletzt bearbeitet 17.08.2026 13:10:02

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to...

  • EPSS 0.09%
  • Veröffentlicht 04.08.2026 05:28:30
  • Zuletzt bearbeitet 18.08.2026 16:37:05

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to t...

  • EPSS 0.1%
  • Veröffentlicht 03.08.2026 15:34:36
  • Zuletzt bearbeitet 21.08.2026 13:16:55

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system...