Redhat

Enterprise Linux

1903 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 21.07.2026 11:32:16
  • Zuletzt bearbeitet 17.08.2026 22:17:15

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

  • EPSS 0.11%
  • Veröffentlicht 21.07.2026 11:26:43
  • Zuletzt bearbeitet 17.08.2026 22:17:15

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

  • EPSS 0.53%
  • Veröffentlicht 21.07.2026 11:16:12
  • Zuletzt bearbeitet 17.08.2026 22:17:15

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

  • EPSS 0.42%
  • Veröffentlicht 21.07.2026 11:08:30
  • Zuletzt bearbeitet 19.08.2026 05:17:04

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote ...

  • EPSS 0.16%
  • Veröffentlicht 21.07.2026 09:16:53
  • Zuletzt bearbeitet 17.08.2026 22:16:59

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long nam...

  • EPSS 0.3%
  • Veröffentlicht 08.07.2026 10:15:30
  • Zuletzt bearbeitet 09.07.2026 19:36:15

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurement...

  • EPSS 0.08%
  • Veröffentlicht 07.07.2026 15:48:04
  • Zuletzt bearbeitet 09.07.2026 20:16:29

A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across ...

  • EPSS 0.31%
  • Veröffentlicht 07.07.2026 13:54:20
  • Zuletzt bearbeitet 09.07.2026 20:20:52

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the...

  • EPSS 0.63%
  • Veröffentlicht 07.07.2026 09:17:36
  • Zuletzt bearbeitet 08.07.2026 21:16:46

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet t...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 07.07.2026 07:44:28
  • Zuletzt bearbeitet 16.07.2026 14:16:55

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, po...