Redhat

Enterprise Linux

1952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.28%
  • Veröffentlicht 06.10.2026 19:34:25
  • Zuletzt bearbeitet 09.10.2026 12:54:42

A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 06.10.2026 19:34:23
  • Zuletzt bearbeitet 09.10.2026 12:56:28

A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, ...

  • EPSS 0.38%
  • Veröffentlicht 01.10.2026 23:27:47
  • Zuletzt bearbeitet 07.10.2026 21:17:20

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade an...

  • EPSS 0.35%
  • Veröffentlicht 01.10.2026 21:29:55
  • Zuletzt bearbeitet 02.10.2026 19:16:42

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thre...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 22.09.2026 15:50:00
  • Zuletzt bearbeitet 07.10.2026 13:41:47

A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorre...

  • EPSS 0.18%
  • Veröffentlicht 22.09.2026 13:11:44
  • Zuletzt bearbeitet 22.09.2026 16:18:21

The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output. The log captures highly sensit...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 14.09.2026 15:55:42
  • Zuletzt bearbeitet 07.10.2026 14:29:19

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become...

  • EPSS 0.56%
  • Veröffentlicht 07.09.2026 14:14:53
  • Zuletzt bearbeitet 08.10.2026 15:17:52

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bin...

  • EPSS 0.84%
  • Veröffentlicht 07.09.2026 14:14:43
  • Zuletzt bearbeitet 08.10.2026 15:17:52

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) prod...

  • EPSS 0.12%
  • Veröffentlicht 03.09.2026 12:23:31
  • Zuletzt bearbeitet 22.09.2026 16:40:21

A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when pro...