Redhat

Openshift Container Platform

348 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.77%
  • Veröffentlicht 30.05.2025 13:13:26
  • Zuletzt bearbeitet 01.09.2026 12:17:22

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, suc...

  • EPSS 0.27%
  • Veröffentlicht 03.03.2025 18:15:30
  • Zuletzt bearbeitet 30.06.2026 00:16:50

A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for ...

  • EPSS 0.28%
  • Veröffentlicht 03.03.2025 17:15:14
  • Zuletzt bearbeitet 30.06.2026 00:16:50

A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. ...

  • EPSS 0.28%
  • Veröffentlicht 03.03.2025 17:15:12
  • Zuletzt bearbeitet 29.06.2026 23:16:41

A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.

  • EPSS 0.22%
  • Veröffentlicht 03.03.2025 17:15:12
  • Zuletzt bearbeitet 29.06.2026 23:16:41

A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the user-provided volume name as input without properly validating the volume name's length. This issue ...

Medienbericht
  • EPSS 7.45%
  • Veröffentlicht 18.02.2025 19:15:29
  • Zuletzt bearbeitet 02.09.2026 02:17:18

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...

  • EPSS 0.23%
  • Veröffentlicht 28.01.2025 10:15:09
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level ...

Exploit
  • EPSS 8.82%
  • Veröffentlicht 14.01.2025 18:15:25
  • Zuletzt bearbeitet 21.09.2026 15:17:25

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of un...

Exploit
  • EPSS 1.83%
  • Veröffentlicht 14.01.2025 18:15:25
  • Zuletzt bearbeitet 21.08.2026 13:16:23

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send chec...

  • EPSS 4.75%
  • Veröffentlicht 14.01.2025 18:15:25
  • Zuletzt bearbeitet 30.06.2026 00:16:48

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, w...