Redhat

Openshift Container Platform

348 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 16:20:17
  • Zuletzt bearbeitet 01.09.2026 12:17:47

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mou...

  • EPSS 0.11%
  • Veröffentlicht 14.08.2026 15:02:26
  • Zuletzt bearbeitet 31.08.2026 18:17:12

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.

  • EPSS 0.11%
  • Veröffentlicht 14.08.2026 05:59:29
  • Zuletzt bearbeitet 02.10.2026 14:17:10

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the st...

  • EPSS 0.12%
  • Veröffentlicht 12.08.2026 15:51:39
  • Zuletzt bearbeitet 01.09.2026 13:18:13

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_cl...

  • EPSS 0.26%
  • Veröffentlicht 11.08.2026 15:34:06
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an...

  • EPSS 0.28%
  • Veröffentlicht 11.08.2026 11:23:59
  • Zuletzt bearbeitet 21.09.2026 17:17:35

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflecti...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 11:23:55
  • Zuletzt bearbeitet 21.09.2026 16:17:08

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egre...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 05.08.2026 12:42:10
  • Zuletzt bearbeitet 21.09.2026 13:17:10

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-t...

  • EPSS 0.13%
  • Veröffentlicht 05.08.2026 12:37:17
  • Zuletzt bearbeitet 21.09.2026 13:17:10

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 05.08.2026 12:16:52
  • Zuletzt bearbeitet 21.09.2026 13:17:09

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for ...