Redhat

Enterprise Linux

1903 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 05.08.2026 12:16:52
  • Zuletzt bearbeitet 19.08.2026 21:17:35

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for ...

  • EPSS 0.13%
  • Veröffentlicht 04.08.2026 18:37:21
  • Zuletzt bearbeitet 17.08.2026 13:10:02

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to...

  • EPSS 0.09%
  • Veröffentlicht 04.08.2026 05:28:30
  • Zuletzt bearbeitet 18.08.2026 16:37:05

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to t...

  • EPSS 0.1%
  • Veröffentlicht 03.08.2026 15:34:36
  • Zuletzt bearbeitet 13.08.2026 16:09:33

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system...

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 14:55:33
  • Zuletzt bearbeitet 09.08.2026 13:54:50

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as fai...

  • EPSS 0.14%
  • Veröffentlicht 03.08.2026 14:51:41
  • Zuletzt bearbeitet 18.08.2026 16:36:55

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can creat...

  • EPSS 0.13%
  • Veröffentlicht 03.08.2026 10:16:33
  • Zuletzt bearbeitet 18.08.2026 16:36:32

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS res...

  • EPSS 0.24%
  • Veröffentlicht 03.08.2026 04:05:30
  • Zuletzt bearbeitet 19.08.2026 20:28:20

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA fi...

  • EPSS 0.69%
  • Veröffentlicht 31.07.2026 09:18:58
  • Zuletzt bearbeitet 18.08.2026 15:16:48

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated repl...

  • EPSS 0.87%
  • Veröffentlicht 31.07.2026 09:18:50
  • Zuletzt bearbeitet 18.08.2026 15:16:49

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checkin...