Redhat

Enterprise Linux

1715 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.41%
  • Veröffentlicht 29.12.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.

  • EPSS 0.06%
  • Veröffentlicht 29.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ when securelev...

  • EPSS 1.02%
  • Veröffentlicht 18.12.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server...

  • EPSS 0.09%
  • Veröffentlicht 18.12.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

  • EPSS 0.07%
  • Veröffentlicht 07.12.2017 02:29:13
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.

  • EPSS 0.05%
  • Veröffentlicht 30.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).

  • EPSS 0.11%
  • Veröffentlicht 15.11.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occur...

  • EPSS 0.06%
  • Veröffentlicht 05.10.2017 01:29:04
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...

Warnung
  • EPSS 57.21%
  • Veröffentlicht 05.10.2017 01:29:04
  • Zuletzt bearbeitet 22.10.2025 00:16:00

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4f...

  • EPSS 0.07%
  • Veröffentlicht 19.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secur...